Executive brief
Oracle GlassFish Server is an application server used to deploy and manage enterprise Java applications. A vulnerability in its security component allows an unauthenticated attacker to remotely access the server via the network. If exploited, this could allow unauthorized individuals to view, modify, or delete sensitive data, and potentially disrupt the availability of the service.
Technical details
This vulnerability exists in the Security subcomponent of Oracle GlassFish Server versions 2.1.1, 3.0.1, and 3.1.2. It is categorized as an 'easily exploitable' flaw that can be triggered by an unauthenticated attacker with network access via LDAP. Successful exploitation allows the attacker to perform unauthorized read, update, insert, or delete operations on a subset of the server's data. Additionally, the vulnerability can be used to cause a partial denial of service (DoS). Oracle addressed this issue in the January 2017 Critical Patch Update.
Affected products
- Oracle GlassFish Server 2.1.1, 3.0.1, 3.1.2
Timeline
- 2017-01-27: disclosed
- 2017-01-27: advisory: Oracle Critical Patch Update published