vendor:
Glassfish Server OSE
by:
Dhiraj Mishra
7.5
CVSS
HIGH
Path Traversal
22
CWE
Product Name: Glassfish Server OSE
Affected Version From: 4.1
Affected Version To: 4.1
Patch Exists: YES
Related CWE: 2017-1000028
CPE: a:oracle:glassfish_server:4.1
Metasploit:
N/A
Other Scripts:
N/A
Platforms Tested: None
2018
Oracle Glassfish OSE 4.1 – Path Traversal (Metasploit)
This module exploits an unauthenticated directory traversal vulnerability which exits in administration console of Oracle GlassFish Server 4.1, which is listening by default on port 4848/TCP.
Mitigation:
The vulnerability can be mitigated by disabling the administration console of Oracle GlassFish Server 4.1.