VYPR

GlassFish

by Eclipse

Source repositories

CVEs (13)

  • CVE-2024-9408CriJul 16, 2025
    risk 0.64cvss 9.8epss 0.00

    In Eclipse GlassFish since version 6.2.5 it is possible to perform a Server Side Request Forgery attack in specific endpoints.

  • CVE-2024-9342CriJul 16, 2025
    risk 0.64cvss 9.8epss 0.00

    In Eclipse GlassFish versions before 8.0.3 it is possible to perform Login Brute Force attacks as there is no limitation in the number of failed login attempts. GlassFish 8.0.3 adds automatic attack protection documented in https://glassfish.org/docs/latest/security-guide.html#b…

  • CVE-2026-12605CriAug 6, 2026
    risk 0.62cvss 9.6epss 0.00

    In Eclipse GlassFish versions 8.0.x before 8.0.4, CSRF + SSRF in DownloadServlet ContentSources leaks the admin `gfresttoken` to attacker-controlled host if the victim is authenticated into the Admin Console -\> full unauthenticated takeover of Eclipse GlassFish domain until the…

  • CVE-2026-2587CriMay 19, 2026
    risk 0.62cvss 9.6epss 0.01

    A critical Remote Code Execution (RCE) vulnerability was identified in the server-side template rendering mechanism used by the Glassfish gadget handler. The application processes .xml files and evaluates user-supplied values within a context where Expression Language (EL)…

  • CVE-2026-2586CriMay 19, 2026
    risk 0.59cvss 9.1epss 0.01

    An authenticated Remote Code Execution (RCE) vulnerability was identified in GlassFish's Administration Console. A user with access to the panel can send crafted requests that allow the execution of arbitrary operating system commands with the privileges of the application…

  • CVE-2023-5763MedNov 3, 2023
    risk 0.44cvss 6.8epss 0.01

    In Eclipse Glassfish 5 or 6, running with old versions of JDK (lower than 6u211, or < 7u201, or < 8u191), allows remote attackers to load malicious code on the server via access to insecure ORB listeners.

  • CVE-2024-9343MedJul 16, 2025
    risk 0.40cvss 6.1epss 0.00

    In Eclipse GlassFish version 7.0.15 is possible to perform Stored Cross-site scripting attacks in the Administration Console.

  • CVE-2024-10029MedJul 16, 2025
    risk 0.40cvss 6.1epss 0.00

    In Eclipse GlassFish version 7.0.15 is possible to perform Reflected Cross-site scripting attacks in the Administration Console.

  • CVE-2024-10032MedJul 16, 2025
    risk 0.35cvss 5.4epss 0.00

    In Eclipse GlassFish version 7.0.15 is possible to perform Stored Cross-site scripting attacks in the Administration Console.

  • CVE-2024-10031MedJul 16, 2025
    risk 0.35cvss 5.4epss 0.00

    In Eclipse GlassFish version 7.0.15 is possible to perform Stored Cross-site Scripting attacks by modifying the configuration file in the underlying operating system.

  • CVE-2022-2712MedJan 27, 2023
    risk 0.35cvss 6.5epss 0.01

    In Eclipse GlassFish versions 5.1.0 to 6.2.5, there is a vulnerability in relative path traversal because it does not filter request path starting with './'. Successful exploitation could allow an remote unauthenticated attacker to access critical data, such as configuration…

  • CVE-2024-9329MedSep 30, 2024
    risk 0.33cvss 6.1epss 0.01

    In Eclipse Glassfish versions before 7.0.17, The Host HTTP parameter could cause the web application to redirect to the specified URL, when the requested endpoint is '/management/domain'. By modifying the URL value to a malicious site, an attacker may successfully launch a…

  • CVE-2024-8646MedSep 11, 2024
    risk 0.33cvss 6.1epss 0.00

    In Eclipse Glassfish versions prior to 7.0.10, a URL redirection vulnerability to untrusted sites existed. This vulnerability is caused by the vulnerability (CVE-2023-41080) in the Apache code included in GlassFish. This vulnerability only affects applications that are…