Junglewise Threat Intelligence

CVE-2017-3239: Oracle GlassFish Server information disclosure in Administration component

CVE-2017-3239 · Severity: low · CVSS 3.3 · Published 2017-01-27

Technologies: Oracle Glassfish Server. Vendors: Oracle.

Executive brief

A vulnerability in the Administration subcomponent of Oracle GlassFish Server could allow an unauthorized user to access sensitive information. An attacker who already has basic access to the server's underlying operating system can exploit this flaw to read a subset of the application server's data. This could lead to the exposure of configuration details or other internal information, though it does not allow the attacker to modify data or shut down the service.

Technical details

An information disclosure vulnerability (CWE-200) exists in the Administration subcomponent of Oracle GlassFish Server versions 3.0.1 and 3.1.2. The flaw is categorized as easily exploitable but requires the attacker to have local logon credentials to the infrastructure where the server is executing (Local attack vector). Successful exploitation allows a low-privileged attacker to gain unauthorized read access to a subset of data accessible by the GlassFish Server process. The vulnerability has a CVSS v3.0 base score of 3.3, reflecting low confidentiality impact with no impact on integrity or availability. Oracle addressed this issue in the January 2017 Critical Patch Update.

Affected products

  • Oracle GlassFish Server 3.0.1, 3.1.2

Timeline

  • 2017-01-27: advisory: Initial NVD publication
  • 2017-01-17: patched: Addressed in Oracle January 2017 Critical Patch Update

References

Related threats