Local File Inclusion Vulnerability in GlassFish Server by Oracle
CVE-2017-1000029

7.5HIGH

Key Information:

Vendor

Oracle

Vendor
CVE Published:
17 July 2017

What is CVE-2017-1000029?

The vulnerability found in Oracle's GlassFish Server Open Source Edition 3.0.1 (build 22) allows attackers to exploit Local File Inclusion (LFI). This enables unauthorized inclusion of arbitrary files on the server without any authentication, potentially leading to sensitive data exposure and system compromise. Organizations using this version should take immediate steps to secure their installations and apply available patches.

References

EPSS Score

72% chance of being exploited in the next 30 days.

CVSS V3.1

Score:
7.5
Severity:
HIGH
Confidentiality:
High
Integrity:
None
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.