VYPR

Maven package

org.apache.openjpa/openjpa

pkg:maven/org.apache.openjpa/openjpa

Vulnerabilities (1)

  • CVE-2013-1768Jul 11, 2013
    affected >= 1.0.0, < 1.2.3fixed 1.2.3

    The BrokerFactory functionality in Apache OpenJPA 1.x before 1.2.3 and 2.x before 2.2.2 creates local executable JSP files containing logging trace data produced during deserialization of certain crafted OpenJPA objects, which makes it easier for remote attackers to execute arbit