Vulnerability in Oracle GlassFish Server Administration Interface
CVE-2017-10400

5.4MEDIUM

Key Information:

Vendor
Oracle
Vendor
CVE Published:
19 October 2017

Summary

A vulnerability exists in the Administration Graphical User Interface of Oracle GlassFish Server, which is part of Oracle Fusion Middleware. This flaw allows unauthenticated attackers with network access through HTTP to gain unauthorized access to sensitive data. Successful exploitation of this vulnerability may require user interaction from individuals who are not the attackers. As a result, single successful attacks could lead to unauthorized modifications, such as updates, inserts, or deletions, along with potential unauthorized reading of some accessible data within the Oracle GlassFish Server.

Affected Version(s)

GlassFish Server 3.1.2

References

CVSS V3.1

Score:
5.4
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.