Junglewise Threat Intelligence

CVE-2017-3250: Oracle GlassFish Server security vulnerability in Security subcomponent

CVE-2017-3250 · Severity: high · CVSS 7.3 · Published 2017-01-27

Technologies: Oracle Glassfish Server. Vendors: Oracle.

Executive brief

Oracle GlassFish Server, a popular application server for hosting Java-based web applications, contains a security vulnerability in its core security component. An unauthenticated attacker can remotely access the server over the network to view, modify, or delete sensitive data. This could lead to unauthorized data manipulation, information disclosure, and partial service outages, potentially disrupting business operations and compromising data integrity.

Technical details

A vulnerability in the Security subcomponent of Oracle GlassFish Server (versions 2.1.1, 3.0.1, and 3.1.2) allows for unauthorized access via the HTTP protocol. The flaw is categorized as an information exposure (CWE-200) but also permits unauthorized data manipulation (INSERT, UPDATE, DELETE). An unauthenticated attacker can exploit this over the network without user interaction to compromise the confidentiality, integrity, and availability of the server. Successful exploitation can result in a partial denial of service (DoS). Oracle addressed this in the January 2017 Critical Patch Update.

Affected products

  • Oracle GlassFish Server 2.1.1, 3.0.1, 3.1.2

Timeline

  • 2017-01-27: advisory: Initial NVD publication
  • 2017-01-27: patched: Addressed in Oracle January 2017 Critical Patch Update

References

Related threats