Oracle GlassFish Server Vulnerability Exposes Data and System Integrity
CVE-2017-3249
7.3HIGH
What is CVE-2017-3249?
This vulnerability in Oracle GlassFish Server allows an unauthenticated attacker with LDAP network access to compromise the server. Attackers can exploit this weakness to gain unauthorized access, enabling them to update, insert, or delete sensitive data. Moreover, it allows for unauthorized read access to a portion of the data and can lead to a partial denial of service (DoS) condition, potentially disrupting operations and affecting data confidentiality and integrity.
Affected Version(s)
GlassFish Server 2.1.1
GlassFish Server 3.0.1
GlassFish Server 3.1.2