Lucene search

K
cve[email protected]CVE-2013-2250
HistoryAug 15, 2013 - 4:55 p.m.

CVE-2013-2250

2013-08-1516:55:09
CWE-20
web.nvd.nist.gov
28
apache
ofbiz
uel
remote code execution
cve-2013-2250
security vulnerability

10 High

CVSS2

Attack Vector

NETWORK

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

COMPLETE

Integrity Impact

COMPLETE

Availability Impact

COMPLETE

AV:N/AC:L/Au:N/C:C/I:C/A:C

7.6 High

AI Score

Confidence

Low

0.007 Low

EPSS

Percentile

79.8%

Apache Open For Business Project (aka OFBiz) 10.04.01 through 10.04.05, 11.04.01 through 11.04.02, and 12.04.01 allows remote attackers to execute arbitrary Unified Expression Language (UEL) functions via JUEL metacharacters in unspecified parameters, related to nested expressions.

Affected configurations

NVD
Node
apacheofbizMatch10.04.01
OR
apacheofbizMatch10.04.02
OR
apacheofbizMatch10.04.03
OR
apacheofbizMatch10.04.04
OR
apacheofbizMatch10.04.05
OR
apacheofbizMatch11.04.01
OR
apacheofbizMatch11.04.02
OR
apacheofbizMatch12.04.01

10 High

CVSS2

Attack Vector

NETWORK

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

COMPLETE

Integrity Impact

COMPLETE

Availability Impact

COMPLETE

AV:N/AC:L/Au:N/C:C/I:C/A:C

7.6 High

AI Score

Confidence

Low

0.007 Low

EPSS

Percentile

79.8%