The BrokerFactory functionality in Apache OpenJPA 1.x before 1.2.3 and 2.x before 2.2.2 creates local executable JSP files containing logging trace data produced during deserialization of certain crafted OpenJPA objects, which makes it easier for remote attackers to execute arbitrary code by creating a serialized object and leveraging improperly secured server programs.
CVSS Details
- CVSS 3.1 Base Score: 9.8
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Debian | — | Upgrade openjpa | Jul 30, 2024 | Jul 11, 2013 |
| Ibm Was | — | Upgrade to version 8.0.0.7.Upgrade to version 8.5.5.Upgrade to minimal fix pack levels as required by interim fixes and then apply Interim Fix PM86780.Upgrade to minimal fix pack levels as required by interim fixes and then apply Interim Fix PM86791.Upgrade to version 7.0.0.29. | Apr 27, 2018 | Jul 11, 2013 |
| Oracle Weblogic | — | Apply the Patch Set Update (PSU) 27342434 for version 12.2.1.3.0. | Apr 18, 2018 | Jul 11, 2013 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub