Executive brief
Oracle GlassFish Server, a platform used for developing and deploying Java applications, contains a critical security vulnerability. An unauthorized attacker could remotely exploit this flaw to take full control of the server. Such an attack could lead to the theft of sensitive data, disruption of business operations, and potential unauthorized access to other connected systems.
Technical details
This vulnerability exists in the Security subcomponent of Oracle GlassFish Server versions 2.1.1, 3.0.1, and 3.1.2. It is classified as a high-complexity attack that can be executed by an unauthenticated attacker with network access via multiple protocols. Successful exploitation results in a complete takeover of the GlassFish Server (impacting Confidentiality, Integrity, and Availability) and carries a 'Scope' change, meaning the impact can extend beyond the GlassFish environment to other products. Oracle addressed this issue in the January 2017 Critical Patch Update.
Affected products
- Oracle GlassFish Server 2.1.1, 3.0.1, 3.1.2
Timeline
- 2017-01-27: disclosed
- 2017-01-27: advisory: Oracle Critical Patch Update published