CVE-2013-2250
Apache Open For Business Project (aka OFBiz) 10.04.01 through 10.04.05, 11.04.01 through 11.04.02, and 12.04.01 allows remote attackers to execute arbitrary Unified Expression Language (UEL) functions via JUEL metacharacters in unspecified parameters,…
Does this matter?
EPSS puts the probability of exploitation in the next 30 days at 12.1%, higher than 96% of all known CVEs. Patch or mitigate before the next change window.
Description
Apache Open For Business Project (aka OFBiz) 10.04.01 through 10.04.05, 11.04.01 through 11.04.02, and 12.04.01 allows remote attackers to execute arbitrary Unified Expression Language (UEL) functions via JUEL metacharacters in unspecified parameters, related to nested expressions.
- CVSS 2.0
- 10.0 HIGHAV:N/AC:L/Au:N/C:C/I:C/A:C
- EPSS
- 12.14% probability · 96th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-20
- Affected
- apache/ofbiz
- Source
- secalert@redhat.com
References
- http://archives.neohapsis.com/archives/bugtraq/2013-07/0143.htmlBroken Link
- http://ofbiz.apache.org/download.html#vulnerabilitiesPatch, Vendor Advisory
- http://osvdb.org/95522Broken Link
- http://secunia.com/advisories/53910Third Party Advisory
- http://www.securityfocus.com/bid/61369Third Party Advisory, VDB Entry
- https://exchange.xforce.ibmcloud.com/vulnerabilities/85875Third Party Advisory, VDB Entry
- http://archives.neohapsis.com/archives/bugtraq/2013-07/0143.htmlBroken Link
- http://ofbiz.apache.org/download.html#vulnerabilitiesPatch, Vendor Advisory
- http://osvdb.org/95522Broken Link
- http://secunia.com/advisories/53910Third Party Advisory
- http://www.securityfocus.com/bid/61369Third Party Advisory, VDB Entry
- https://exchange.xforce.ibmcloud.com/vulnerabilities/85875Third Party Advisory, VDB Entry
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.