← All CVEs

CVE-2013-2250

high · 10

Apache Open For Business Project (aka OFBiz) 10.04.01 through 10.04.05, 11.04.01 through 11.04.02, and 12.04.01 allows remote attackers to execute arbitrary Unified Expression Language (UEL) functions via JUEL metacharacters in unspecified parameters, related to nested expressions.

10
CVSS
12.1%
EPSS (exploit prob.)
96th
EPSS percentile
2013-08-15
Published

AV:N/AC:L/Au:N/C:C/I:C/A:C

Weaknesses

CWE-20

Affected products

VendorProductAffected versions
apacheofbiz10.04.01
apacheofbiz10.04.02
apacheofbiz10.04.03
apacheofbiz10.04.04
apacheofbiz10.04.05
apacheofbiz11.04.01
apacheofbiz11.04.02
apacheofbiz12.04.01

Check a specific version with /api/v1/cve/match.

References

Query this programmatically:

curl https://evil-db.io/api/v1/cve/CVE-2013-2250