CVE-2013-2250 - Apache OFBiz Nested expression evaluation allows remote users to execute arbitrary UEL functions in OFBiz Vendor: The Apache Software Foundation Versions Affected: Apache OFBiz 10.04.01 to 10.04.05 Apache OFBiz 11.04.01 to 11.04.02 Apache OFBiz 12.04.01 Description: Parameter values are not correctly validated and if JUEL metacharacters are included they are interpreted. Mitigation: 10.04.x users should upgrade to 10.04.06 11.04.x users should upgrade to 11.04.03 12.04.01 users should upgrade to 12.04.02 Credit: This issue was discovered by Grégory Draperi (gregory.draperi@gmail.com). References: http://ofbiz.apache.org/download.html#vulnerabilities