Known Vulnerabilities for Java System Application Server by Sun

Listed below are 10 of the newest known vulnerabilities associated with "Java System Application Server" by "Sun".

These CVEs are retrieved based on exact matches on listed software, hardware, and vendor information (CPE data) as well as a keyword search to ensure the newest vulnerabilities with no officially listed software information are still displayed.

Data on known vulnerable versions is also displayed based on information from known CPEs

Known Vulnerabilities

CVE Shortened Description Severity Publish Date Last Modified
CVE-2012-3155 Unspecified vulnerability in the CORBA ORB component in Sun GlassFish Enterprise Server 2.1.1, Oracle GlassFish Server 3.0.1 ... 5 - MEDIUM 2012-10-16 2013-10-11
CVE-2011-0807 Unspecified vulnerability in Oracle Sun GlassFish Enterprise Server 2.1, 2.1.1, and 3.0.1, and Sun Java System Application Se... 10 - HIGH 2011-04-20 2011-09-22
CVE-2010-0386 The default configuration of Sun Java System Application Server 7 and 7 2004Q2 enables the HTTP TRACE method, which makes it ... 4.3 - MEDIUM 2010-01-25 2010-01-31
CVE-2009-0278 Sun Java System Application Server (AS) 8.1 and 8.2 allows remote attackers to read the Web Application configuration files i... 5 - MEDIUM 2009-01-27 2017-08-08
CVE-2008-5266 Cross-site scripting (XSS) vulnerability in configuration/httpListenerEdit.jsf in the GlassFish 2 UR2 b04 webadmin interface ... 4.3 - MEDIUM 2008-11-28 2018-10-11
CVE-2008-2751 Multiple cross-site scripting (XSS) vulnerabilities in the Glassfish webadmin interface in Sun Java System Application Server... 4.3 - MEDIUM 2008-06-18 2018-10-11
CVE-2008-2120 Unspecified vulnerability in Sun Java System Application Server 7 2004Q2 before Update 6, Web Server 6.1 before SP8, and Web ... 5 - MEDIUM 2008-05-09 2017-08-08
CVE-2007-4511 The Sun Admin Console in Sun Application Server 9.0_0.1 does not apply certain configuration changes persistently, which caus... 5 - MEDIUM 2007-08-23 2018-10-15
CVE-2007-4025 Unspecified vulnerability in Sun Java System (SJS) Application Server 8.1 through 9.0 before 20070724 on Windows allows remot... 4.3 - MEDIUM 2007-07-26 2017-07-29
CVE-2007-3715 Sun Java System Application Server and Web Server 7.0 through 9.0 before 20070710 do not properly process XSLT stylesheets in... 9.3 - HIGH 2007-07-11 2018-10-15

Known Affected Configurations (CPE V2.3)

Type Vendor Product Version Update Edition Language
ApplicationSunJava System Application Server9.1AllAllAll
ApplicationSunJava System Application Server9.0_0.1AllAllAll
ApplicationSunJava System Application Server9.0AllAllAll
ApplicationSunJava System Application Server8.2Allx86All
ApplicationSunJava System Application Server8.2AllwindowsAll
ApplicationSunJava System Application Server8.2AllsparcAll
ApplicationSunJava System Application Server8.2AlllinuxAll
ApplicationSunJava System Application Server8.2AllAllAll
ApplicationSunJava System Application Server8.1ur1AllAll
ApplicationSunJava System Application Server8.1ur1platformAll
ApplicationSunJava System Application Server8.1Allx86All
ApplicationSunJava System Application Server8.1AllwindowsAll
ApplicationSunJava System Application Server8.1AllsparcAll
ApplicationSunJava System Application Server8.1AlllinuxAll
ApplicationSunJava System Application Server8.1AllAllAll
ApplicationSunJava System Application Server7.1AllAllAll
ApplicationSunJava System Application Server7.0AllAllAll
ApplicationSunJava System Application Server6.0AllAllAll
ApplicationSunJava System Application Server-AllAllAll
© CVE.report 2026 |

Use of this information constitutes acceptance for use in an AS IS condition. There are NO warranties, implied or otherwise, with regard to this information or its use. Any use of this information is at the user's risk. It is the responsibility of user to evaluate the accuracy, completeness or usefulness of any information, opinion, advice or other content. EACH USER WILL BE SOLELY RESPONSIBLE FOR ANY consequences of his or her direct or indirect use of this web site. ALL WARRANTIES OF ANY KIND ARE EXPRESSLY DISCLAIMED. This site will NOT BE LIABLE FOR ANY DIRECT, INDIRECT or any other kind of loss.

CVE, CWE, and OVAL are registred trademarks of The MITRE Corporation and the authoritative source of CVE content is MITRE's CVE web site. This site includes MITRE data granted under the following license.

CVE.report and Source URL Uptime Status status.cve.report