Oracle, GlassFish Server Open Source Edition 3.0.1 (build 22) is vulnerable to Local File Inclusion vulnerability, that makes it possible to include arbitrary files on the server, this vulnerability can be exploited without any prior authentication.
References
Link | Resource |
---|---|
https://www.trustwave.com/Resources/Security-Advisories/Advisories/TWSL2016-011/?fid=8037 | Mailing List Third Party Advisory |
Configurations
Information
Published : 2017-07-17 06:18
Updated : 2017-07-21 09:10
NVD link : CVE-2017-1000029
Mitre link : CVE-2017-1000029
JSON object : View
CWE
CWE-200
Exposure of Sensitive Information to an Unauthorized Actor
Products Affected
oracle
- glassfish_server