Oracle Sun GlassFish/Java System Application Server Remote Authentication Bypass Vulnerability
BID:47438
Info
Oracle Sun GlassFish/Java System Application Server Remote Authentication Bypass Vulnerability
| Bugtraq ID: | 47438 |
| Class: | Unknown |
| CVE: |
CVE-2011-0807 |
| Remote: | Yes |
| Local: | No |
| Published: | Apr 19 2011 12:00AM |
| Updated: | Jun 30 2014 10:40AM |
| Credit: | Jason Bowes |
| Vulnerable: |
Sun Java System Application Server Platform Edition 9.1 Sun Glassfish Enterprise Server 3.0.1 Sun Glassfish Enterprise Server 2.1.1 Sun Glassfish Enterprise Server 2.1 |
| Not Vulnerable: | |
Discussion
Oracle Sun GlassFish/Java System Application Server Remote Authentication Bypass Vulnerability
Oracle Sun GlassFish/Java System Application Server is prone to a remote authentication-bypass vulnerability.
The vulnerability can be exploited over the 'HTTP' protocol. The 'Administration' sub component is affected.
Attackers can exploit this issue to bypass authentication and perform unauthorized actions.
This vulnerability affects the following supported versions:
2.1, 2.1.1, 3.0.1, 9.1
Oracle Sun GlassFish/Java System Application Server is prone to a remote authentication-bypass vulnerability.
The vulnerability can be exploited over the 'HTTP' protocol. The 'Administration' sub component is affected.
Attackers can exploit this issue to bypass authentication and perform unauthorized actions.
This vulnerability affects the following supported versions:
2.1, 2.1.1, 3.0.1, 9.1
Exploit / POC
Oracle Sun GlassFish/Java System Application Server Remote Authentication Bypass Vulnerability
The following Metasploit exploit module is available:
The following Metasploit exploit module is available:
Solution / Fix
Oracle Sun GlassFish/Java System Application Server Remote Authentication Bypass Vulnerability
Solution:
Vendor updates are available. Please contact the vendor for more information.
Solution:
Vendor updates are available. Please contact the vendor for more information.
References
Oracle Sun GlassFish/Java System Application Server Remote Authentication Bypass Vulnerability
References:
References: