CVE-2009-1553
Summary
| CVE | CVE-2009-1553 |
|---|---|
| State | PUBLISHED |
| Assigner | mitre |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2009-05-06 16:30:00 UTC |
| Updated | 2026-04-23 00:35:47 UTC |
| Description | Multiple cross-site scripting (XSS) vulnerabilities in the Admin Console in Sun GlassFish Enterprise Server 2.1 allow remote attackers to inject arbitrary web script or HTML via the query string to (1) applications/applications.jsf, (2) configuration/configuration.jsf, (3) customMBeans/customMBeans.jsf, (4) resourceNode/resources.jsf, (5) sysnet/registration.jsf, or (6) webService/webServicesGeneral.jsf; or the name parameter to (7) configuration/auditModuleEdit.jsf, (8) configuration/httpListenerEdit.jsf, or (9) resourceNode/jdbcResourceEdit.jsf. |
Risk And Classification
CVSS v2.0 Breakdown
Access Vector
NetworkAccess Complexity
MediumAuthentication
NoneConfidentiality
NoneIntegrity
PartialAvailability
NoneAV:N/AC:M/Au:N/C:N/I:P/A:N
NVD Known Affected Configurations (CPE 2.3)
| Type | Vendor | Product | Version | Update | Edition | Language |
|---|---|---|---|---|---|---|
| Application | Oracle | Glassfish Server | 2.1 | All | All | All |
Vendor Declared Affected Products
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| osvdb.org/54252 | af854a3a-2127-422b-91ae-364da2661108 | osvdb.org | |
| Sun GlassFish Enterprise and Sun Java System Application Server Cross Site Scripting Vulnerabilities | af854a3a-2127-422b-91ae-364da2661108 | www.securityfocus.com | |
| osvdb.org/54253 | af854a3a-2127-422b-91ae-364da2661108 | osvdb.org | |
| osvdb.org/54250 | af854a3a-2127-422b-91ae-364da2661108 | osvdb.org | |
| osvdb.org/54251 | af854a3a-2127-422b-91ae-364da2661108 | osvdb.org | |
| osvdb.org/54257 | af854a3a-2127-422b-91ae-364da2661108 | osvdb.org | |
| osvdb.org/54256 | af854a3a-2127-422b-91ae-364da2661108 | osvdb.org | |
| IBM X-Force Exchange | af854a3a-2127-422b-91ae-364da2661108 | exchange.xforce.ibmcloud.com | |
| osvdb.org/54255 | af854a3a-2127-422b-91ae-364da2661108 | osvdb.org | |
| osvdb.org/54254 | af854a3a-2127-422b-91ae-364da2661108 | osvdb.org | |
| Digital Security Research Group - [DSECRG-09-034] Sun Glassfish Enterprise Server - Multiple Linked XSS vulnerabilies | af854a3a-2127-422b-91ae-364da2661108 | dsecrg.com | Exploit |
| Webmail : Solution de messagerie professionnelle - OVHcloud- OVH | af854a3a-2127-422b-91ae-364da2661108 | www.vupen.com | |
| Java.net Maintenance outage | af854a3a-2127-422b-91ae-364da2661108 | glassfish.dev.java.net | Patch, Vendor Advisory |
| JVNDB-2009-000027 - JVN iPedia | af854a3a-2127-422b-91ae-364da2661108 | jvndb.jvn.jp | |
| Nabble - [DSECRG] Sun Glassfish Multiple Security Vulnerabilities | af854a3a-2127-422b-91ae-364da2661108 | www.nabble.com | Exploit |
| sunsolve.sun.com/search/document.do | af854a3a-2127-422b-91ae-364da2661108 | sunsolve.sun.com | |
| JVN#73653977 Sun GlassFish Enterprise Server and Sun Java System Application Server vulnerable to cross-site scripting | af854a3a-2127-422b-91ae-364da2661108 | jvn.jp | |
| Old Nabble - Re: [DSECRG] Sun Glassfish Multiple Security Vulnerabilities | af854a3a-2127-422b-91ae-364da2661108 | www.nabble.com | |
| GlassFish Enterprise Server Multiple Cross Site Scripting Vulnerabilities | af854a3a-2127-422b-91ae-364da2661108 | www.securityfocus.com | Exploit |
| Java.net Maintenance outage | af854a3a-2127-422b-91ae-364da2661108 | glassfish.dev.java.net | Patch, Vendor Advisory |
| osvdb.org/54249 | af854a3a-2127-422b-91ae-364da2661108 | osvdb.org | |
| SecurityFocus | af854a3a-2127-422b-91ae-364da2661108 | www.securityfocus.com | |
| Java.net Maintenance outage | af854a3a-2127-422b-91ae-364da2661108 | glassfish.dev.java.net | Patch, Vendor Advisory |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
No vendor comments have been submitted for this CVE.
There are currently no legacy QID mappings associated with this CVE.