Vulnerability in Oracle Fusion Middleware's GlassFish Server
CVE-2017-10393
6.3MEDIUM
Summary
An unauthenticated access vulnerability exists in the Oracle GlassFish Server component of Oracle Fusion Middleware, specifically in the Web Container subcomponent. The vulnerability is easily exploitable by attackers who have network access via HTTP. Successful exploitation requires human interaction from users other than the attacker. The result could be unauthorized access to sensitive data, allowing for updates, inserts, and deletions to the accessible data on the server, along with a potential partial denial of service. Notably, this affects users of Oracle GlassFish Server versions 3.0.1 and 3.1.2.
Affected Version(s)
GlassFish Server 3.0.1
GlassFish Server 3.1.2
References
CVSS V3.1
Score:
6.3
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Unchanged
Timeline
Vulnerability published
Vulnerability Reserved