CVE-2013-2250
published 2013-08-15CVE-2013-2250: Apache Open For Business Project (aka OFBiz) 10.04.01 through 10.04.05, 11.04.01 through 11.04.02, and 12.04.01 allows remote attackers to execute arbitrary…
PriorityP358critical10CVSS 2.0
AVNACLAuNCCICAC
EPSS
12.14%
95.7th percentile
Apache Open For Business Project (aka OFBiz) 10.04.01 through 10.04.05, 11.04.01 through 11.04.02, and 12.04.01 allows remote attackers to execute arbitrary Unified Expression Language (UEL) functions via JUEL metacharacters in unspecified parameters, related to nested expressions.
Affected
9 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| apache | ofbiz | — | — |
| apache | ofbiz | — | — |
| apache | ofbiz | — | — |
| apache | ofbiz | — | — |
| apache | ofbiz | — | — |
| apache | ofbiz | — | — |
| apache | ofbiz | — | — |
| apache | ofbiz | — | — |
| apache | ofbiz | — | — |
CVSS provenance
nvdv2.010.0CRITICALAV:N/AC:L/Au:N/C:C/I:C/A:C
vendor_apache10.0CRITICAL
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-4xmq-9x3w-xpvr: Apache Open For Business Project (aka OFBiz) 10
ghsa_unreviewed·2022-05-14
CVE-2013-2250 [HIGH] CWE-20 GHSA-4xmq-9x3w-xpvr: Apache Open For Business Project (aka OFBiz) 10
Apache Open For Business Project (aka OFBiz) 10.04.01 through 10.04.05, 11.04.01 through 11.04.02, and 12.04.01 allows remote attackers to execute arbitrary Unified Expression Language (UEL) functions via JUEL metacharacters in unspecified parameters, related to nested expressions.
Apache
Apache ofbiz: CVE-2013-2250
vendor_apache·CVSS 10.0
CVE-2013-2250 [CRITICAL] Apache ofbiz: CVE-2013-2250
Apache ofbiz: CVE-2013-2250
; affected releases: 12.04.01, 11.04.02 and earlier versions (11.04.*), 10.04.05 and earlier versions (10.04.*); fixed in 12.04.02, 11.04.03 and 10.04.06
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
http://archives.neohapsis.com/archives/bugtraq/2013-07/0143.htmlhttp://ofbiz.apache.org/download.html#vulnerabilitieshttp://osvdb.org/95522http://secunia.com/advisories/53910http://www.securityfocus.com/bid/61369https://exchange.xforce.ibmcloud.com/vulnerabilities/85875http://archives.neohapsis.com/archives/bugtraq/2013-07/0143.htmlhttp://ofbiz.apache.org/download.html#vulnerabilitieshttp://osvdb.org/95522http://secunia.com/advisories/53910http://www.securityfocus.com/bid/61369https://exchange.xforce.ibmcloud.com/vulnerabilities/85875
2013-08-15
Published