SB2013032801 - Remote code execution in Apache OpenJPA



SB2013032801 - Remote code execution in Apache OpenJPA

Published: March 28, 2018

Security Bulletin ID SB2013032801
Severity
High
Patch available
YES
Number of vulnerabilities 1
Exploitation vector Remote access
Highest impact Code execution

Breakdown by Severity

High 100%
  • Low
  • Medium
  • High
  • Critical

Description

This security bulletin contains information about 1 security vulnerability.


1) Deserialization of untrusted data (CVE-ID: CVE-2013-1768)

The vulnerability allows a remote attacker to execute arbitrary code on the target system.

The weakness exists due to in the BrokerFactory functionality due to creating local executable JSP files containing logging trace data produced during deserialization of certain crafted OpenJPA objects. A remote attacker can create a serialized object, leverage improperly secured server programs and execute arbitrary code.

Successful exploitation of the vulnerability my result in system compromise.

Remediation

Install update from vendor's website.