Known Vulnerabilities for Glassfish Server by Oracle
Listed below are 10 of the newest known vulnerabilities associated with "Glassfish Server" by "Oracle".
These CVEs are retrieved based on exact matches on listed software, hardware, and vendor information (CPE data) as well as a keyword search to ensure the newest vulnerabilities with no officially listed software information are still displayed.
Data on known vulnerable versions is also displayed based on information from known CPEs
Known Vulnerabilities
| CVE | Shortened Description | Severity | Publish Date | Last Modified |
|---|---|---|---|---|
| CVE-2021-3314 json | ** UNSUPPORTED WHEN ASSIGNED ** Oracle GlassFish Server 3.1.2.18 and below allows /common/logViewer/logViewer.jsf XSS. A mali... | 6.1 - MEDIUM | 2021-06-25 | 2023-11-07 |
| CVE-2018-14324 json | The demo feature in Oracle GlassFish Open Source Edition 5.0 has TCP port 7676 open by default with a password of admin for t... | 9.8 - CRITICAL | 2018-07-16 | 2019-05-20 |
| CVE-2018-3210 json | Vulnerability in the Oracle GlassFish Server component of Oracle Fusion Middleware (subcomponent: Java Server Faces). The sup... | 5.3 - MEDIUM | 2018-10-17 | 2019-10-03 |
| CVE-2018-3152 json | Vulnerability in the Oracle GlassFish Server component of Oracle Fusion Middleware (subcomponent: Administration). The suppor... | 7.5 - HIGH | 2018-10-17 | 2019-10-03 |
| CVE-2018-2911 json | Vulnerability in the Oracle GlassFish Server component of Oracle Fusion Middleware (subcomponent: Java Server Faces). The sup... | 8.3 - HIGH | 2018-10-17 | 2019-10-03 |
| CVE-2017-1000030 json | Oracle, GlassFish Server Open Source Edition 3.0.1 (build 22) is vulnerable to Java Key Store Password Disclosure vulnerabili... | 9.8 - CRITICAL | 2017-07-17 | 2017-07-21 |
| CVE-2017-1000029 json | Oracle, GlassFish Server Open Source Edition 3.0.1 (build 22) is vulnerable to Local File Inclusion vulnerability, that makes... | 7.5 - HIGH | 2017-07-17 | 2017-07-21 |
| CVE-2017-1000028 json | Oracle, GlassFish Server Open Source Edition 4.1 is vulnerable to both authenticated and unauthenticated Directory Traversal ... | 7.5 - HIGH | 2017-07-17 | 2019-05-03 |
| CVE-2017-10400 json | Vulnerability in the Oracle GlassFish Server component of Oracle Fusion Middleware (subcomponent: Administration Graphical Us... | 5.4 - MEDIUM | 2017-10-19 | 2019-10-03 |
| CVE-2017-10393 json | Vulnerability in the Oracle GlassFish Server component of Oracle Fusion Middleware (subcomponent: Web Container). Supported v... | 6.3 - MEDIUM | 2017-10-19 | 2019-10-03 |
Known Affected Configurations (CPE V2.3)
| Type | Vendor | Product | Version | Update | Edition | Language |
|---|---|---|---|---|---|---|
| Application | Oracle | Glassfish Server | 5.0 | |||
| Application | Oracle | Glassfish Server | 4.1 | |||
| Application | Oracle | Glassfish Server | 3_prelude | |||
| Application | Oracle | Glassfish Server | 3.1.2 | |||
| Application | Oracle | Glassfish Server | 3.1.1 | |||
| Application | Oracle | Glassfish Server | 3.1 | |||
| Application | Oracle | Glassfish Server | 3.0.1 | |||
| Application | Oracle | Glassfish Server | 3.0.1 | |||
| Application | Oracle | Glassfish Server | 3.0 | |||
| Application | Oracle | Glassfish Server | 2.1.1 | |||
| Application | Oracle | Glassfish Server | 2.1 | |||
| Application | Oracle | Glassfish Server | 2.0 | |||
| Application | Oracle | Glassfish Server | 2 | |||
| Application | Oracle | Glassfish Server | 2 | |||
| Application | Oracle | Glassfish Server | 1.0 | |||
| Application | Oracle | Glassfish Server | 1.0 | |||
| Application | Oracle | Glassfish Server | 1.0 |