Local File Inclusion Vulnerability in GlassFish Server by Oracle
CVE-2017-1000029

7.5HIGH

Key Information:

Vendor
Oracle
Vendor
CVE Published:
17 July 2017

Summary

The vulnerability found in Oracle's GlassFish Server Open Source Edition 3.0.1 (build 22) allows attackers to exploit Local File Inclusion (LFI). This enables unauthorized inclusion of arbitrary files on the server without any authentication, potentially leading to sensitive data exposure and system compromise. Organizations using this version should take immediate steps to secure their installations and apply available patches.

References

EPSS Score

62% chance of being exploited in the next 30 days.

CVSS V3.1

Score:
7.5
Severity:
HIGH
Confidentiality:
High
Integrity:
None
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.