Oracle Glassfish Server vulnerabilities
40 known vulnerabilities affecting oracle/glassfish_server.
Total CVEs
40
CISA KEV
0
Public exploits
9
Exploited in wild
1
Severity breakdown
CRITICAL6HIGH10MEDIUM20LOW4
Vulnerabilities
Page 2 of 2
CVE-2017-3250P3HIGHCVSS 7.3v2.1.1v3.0.1+1 more2017-01-27
CVE-2017-3250 [HIGH] CWE-200 CVE-2017-3250: Vulnerability in the Oracle GlassFish Server component of Oracle Fusion Middleware (subcomponent: Se
Vulnerability in the Oracle GlassFish Server component of Oracle Fusion Middleware (subcomponent: Security). Supported versions that are affected are 2.1.1, 3.0.1 and 3.1.2. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle GlassFish Server. Successful attacks of this vulnerability can res
nvd
CVE-2011-3559P3HIGHCVSS 7.8v2.1.1v3.0.1+1 more2011-10-18
CVE-2011-3559 [HIGH] CVE-2011-3559: Unspecified vulnerability in Oracle Communications Server 2.0; GlassFish Enterprise Server 2.1.1, 3.
Unspecified vulnerability in Oracle Communications Server 2.0; GlassFish Enterprise Server 2.1.1, 3.0.1, and 3.1.1; and Sun Java System App Server 8.1 and 8.2 allows remote attackers to affect availability via unknown vectors related to Web Container.
nvd
CVE-2015-3237P4MEDIUMCVSS 6.4v3.0.1v3.1.22015-06-22
CVE-2015-3237 [MEDIUM] CWE-20 CVE-2015-3237: The smb_request_state function in cURL and libcurl 7.40.0 through 7.42.1 allows remote SMB servers t
The smb_request_state function in cURL and libcurl 7.40.0 through 7.42.1 allows remote SMB servers to obtain sensitive information from memory or cause a denial of service (out-of-bounds read and crash) via crafted length and offset values.
nvd
CVE-2017-10385P4MEDIUMCVSS 6.3v3.0.1v3.1.22017-10-19
CVE-2017-10385 [MEDIUM] CVE-2017-10385: Vulnerability in the Oracle GlassFish Server component of Oracle Fusion Middleware (subcomponent: We
Vulnerability in the Oracle GlassFish Server component of Oracle Fusion Middleware (subcomponent: Web Container). Supported versions that are affected are 3.0.1 and 3.1.2. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle GlassFish Server. Successful attacks require human interaction from a pe
nvd
CVE-2017-10393P4MEDIUMCVSS 6.3v3.0.1v3.1.22017-10-19
CVE-2017-10393 [MEDIUM] CVE-2017-10393: Vulnerability in the Oracle GlassFish Server component of Oracle Fusion Middleware (subcomponent: We
Vulnerability in the Oracle GlassFish Server component of Oracle Fusion Middleware (subcomponent: Web Container). Supported versions that are affected are 3.0.1 and 3.1.2. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle GlassFish Server. Successful attacks require human interaction from a pe
nvd
CVE-2016-5477P4MEDIUMCVSS 5.8v2.1.1v3.0.12016-07-21
CVE-2016-5477 [MEDIUM] CVE-2016-5477: Unspecified vulnerability in the Oracle GlassFish Server component in Oracle Fusion Middleware 2.1.1
Unspecified vulnerability in the Oracle GlassFish Server component in Oracle Fusion Middleware 2.1.1 and 3.0.1 allows remote attackers to affect confidentiality via vectors related to Administration.
nvd
CVE-2016-3608P4MEDIUMCVSS 5.8v3.0.12016-07-21
CVE-2016-3608 [MEDIUM] CVE-2016-3608: Unspecified vulnerability in the Oracle GlassFish Server component in Oracle Fusion Middleware 3.0.1
Unspecified vulnerability in the Oracle GlassFish Server component in Oracle Fusion Middleware 3.0.1 allows remote attackers to affect confidentiality via vectors related to Administration.
nvd
CVE-2018-3210P4MEDIUMCVSS 5.3v3.1.22018-10-17
CVE-2018-3210 [MEDIUM] CVE-2018-3210: Vulnerability in the Oracle GlassFish Server component of Oracle Fusion Middleware (subcomponent: Ja
Vulnerability in the Oracle GlassFish Server component of Oracle Fusion Middleware (subcomponent: Java Server Faces). The supported version that is affected is 3.1.2. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle GlassFish Server. Successful attacks of this vulnerability can result in unauth
nvd
CVE-2017-10400P4MEDIUMCVSS 5.4v3.1.22017-10-19
CVE-2017-10400 [MEDIUM] CVE-2017-10400: Vulnerability in the Oracle GlassFish Server component of Oracle Fusion Middleware (subcomponent: Ad
Vulnerability in the Oracle GlassFish Server component of Oracle Fusion Middleware (subcomponent: Administration Graphical User Interface). The supported version that is affected is 3.1.2. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle GlassFish Server. Successful attacks require human inte
nvd
CVE-2012-3155P4MEDIUMCVSS 5.0v2.1.1v3.0.1+1 more2012-10-16
CVE-2012-3155 [MEDIUM] CVE-2012-3155: Unspecified vulnerability in the CORBA ORB component in Sun GlassFish Enterprise Server 2.1.1, Oracl
Unspecified vulnerability in the CORBA ORB component in Sun GlassFish Enterprise Server 2.1.1, Oracle GlassFish Server 3.0.1 and 3.1.2, and Sun Java System Application Server 8.1 and 8.2 allows remote attackers to affect availability, related to CORBA ORB.
nvd
CVE-2021-3314P4MEDIUMCVSS 6.1≤ 3.1.2.182021-06-25
CVE-2021-3314 [MEDIUM] CWE-79 CVE-2021-3314: Oracle GlassFish Server 3.1.2.18 and below allows /common/logViewer/logViewer.jsf XSS. A malicious u
Oracle GlassFish Server 3.1.2.18 and below allows /common/logViewer/logViewer.jsf XSS. A malicious user can cause an administrator user to supply dangerous content to the vulnerable page, which is then reflected back to the user and executed by the web browser. The most common mechanism for delivering malicious content is to include it as a parameter i
nvd
CVE-2013-1620P4MEDIUMCVSS 4.3v2.1.12013-02-08
CVE-2013-1620 [MEDIUM] CVE-2013-1620: The TLS implementation in Mozilla Network Security Services (NSS) does not properly consider timing
The TLS implementation in Mozilla Network Security Services (NSS) does not properly consider timing side-channel attacks on a noncompliant MAC check operation during the processing of malformed CBC padding, which allows remote attackers to conduct distinguishing attacks and plaintext-recovery attacks via statistical analysis of timing data for crafted packets,
nvd
CVE-2012-0104P4MEDIUMCVSS 5.0v3.0.1v3.1.12012-01-18
CVE-2012-0104 [MEDIUM] CVE-2012-0104: Unspecified vulnerability in Oracle GlassFish Enterprise Server 3.0.1 and 3.1.1 allows remote attack
Unspecified vulnerability in Oracle GlassFish Enterprise Server 3.0.1 and 3.1.1 allows remote attackers to affect availability via unknown vectors related to Web Container.
nvd
CVE-2017-3247P4MEDIUMCVSS 4.3v2.1.1v3.0.1+1 more2017-01-27
CVE-2017-3247 [MEDIUM] CVE-2017-3247: Vulnerability in the Oracle GlassFish Server component of Oracle Fusion Middleware (subcomponent: Co
Vulnerability in the Oracle GlassFish Server component of Oracle Fusion Middleware (subcomponent: Core). Supported versions that are affected are 2.1.1, 3.0.1 and 3.1.2. Easily exploitable vulnerability allows unauthenticated attacker with network access via SMTP to compromise Oracle GlassFish Server. Successful attacks require human interaction from a person
nvd
CVE-2013-1508P4MEDIUMCVSS 4.3v3.0.1v3.1.22013-04-17
CVE-2013-1508 [MEDIUM] CVE-2013-1508: Unspecified vulnerability in the Oracle GlassFish Server component in Oracle Sun Middleware Products
Unspecified vulnerability in the Oracle GlassFish Server component in Oracle Sun Middleware Products 3.0.1 and 3.1.2 allows remote attackers to affect integrity via vectors related to REST Interface.
nvd
CVE-2010-4438P4MEDIUMCVSS 5.7v2.1v2.1.1+1 more2011-01-19
CVE-2010-4438 [MEDIUM] CVE-2010-4438: Unspecified vulnerability in Oracle GlassFish 2.1, 2.1.1, and 3.0.1, and Java System Message Queue 4
Unspecified vulnerability in Oracle GlassFish 2.1, 2.1.1, and 3.0.1, and Java System Message Queue 4.1 allows local users to affect confidentiality, integrity, and availability, related to Java Message Service (JMS).
nvd
CVE-2017-3626P4LOWCVSS 3.1v3.1.22017-04-24
CVE-2017-3626 [LOW] CVE-2017-3626: Vulnerability in the Oracle GlassFish Server component of Oracle Fusion Middleware (subcomponent: Ja
Vulnerability in the Oracle GlassFish Server component of Oracle Fusion Middleware (subcomponent: Java Server Faces). The supported version that is affected is 3.1.2. Difficult to exploit vulnerability allows unauthenticated attacker with network access via multiple protocols to compromise Oracle GlassFish Server. Successful attacks require human interaction fro
nvd
CVE-2012-0081P4LOWCVSS 3.7v3.1.12012-01-18
CVE-2012-0081 [LOW] CVE-2012-0081: Unspecified vulnerability in Oracle GlassFish Enterprise Server 3.1.1 allows local users to affect c
Unspecified vulnerability in Oracle GlassFish Enterprise Server 3.1.1 allows local users to affect confidentiality, integrity, and availability via unknown vectors related to Administration.
nvd
CVE-2017-3239P4LOWCVSS 3.3v3.0.1v3.1.22017-01-27
CVE-2017-3239 [LOW] CWE-200 CVE-2017-3239: Vulnerability in the Oracle GlassFish Server component of Oracle Fusion Middleware (subcomponent: Ad
Vulnerability in the Oracle GlassFish Server component of Oracle Fusion Middleware (subcomponent: Administration). Supported versions that are affected are 3.0.1 and 3.1.2. Easily exploitable vulnerability allows low privileged attacker with logon to the infrastructure where Oracle GlassFish Server executes to compromise Oracle GlassFish Server. Successf
nvd
CVE-2010-2397P4LOWCVSS 2.4v2.1.12010-07-13
CVE-2010-2397 [LOW] CVE-2010-2397: Unspecified vulnerability in Oracle Sun Java System Application Server 8.0, 8.1, and 8.2; and GlassF
Unspecified vulnerability in Oracle Sun Java System Application Server 8.0, 8.1, and 8.2; and GlassFish Enterprise Server 2.1.1; allows local users to affect confidentiality and integrity, related to the GUI.
nvd
← Previous2 / 2