Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

CVE-2013-3827

46
FAUCET Score

CVE-2013-3827 is an unspecified vulnerability impacting Oracle GlassFish Server, JDeveloper, and WebLogic Server components within Oracle Fusion Middleware. It allows remote attackers to compromise confidentiality through unknown vectors related to Java Server Faces or Web Container. With a CVSS score of 5.0, this vulnerability is easily exploitable over the network without authentication, potentially leading to information disclosure. While not actively exploited in the wild, public exploit code exists, including a Metasploit module and Nuclei templates, indicating a high potential for exploitation. Despite its high FAUCET Risk Score of 99/100 and high EPSS, there is minimal community discussion or media coverage.

Impacted Technologies

VendorProductVersion(s)CPE
2.1.1CPE matchmatch criteria
cpe:2.3:a:oracle:fusion_middleware:2.1.1:*:*:*:*:*:*:*
3.0.1CPE matchmatch criteria
cpe:2.3:a:oracle:fusion_middleware:3.0.1:*:*:*:*:*:*:*
3.1.2CPE matchmatch criteria
cpe:2.3:a:oracle:fusion_middleware:3.1.2:*:*:*:*:*:*:*
10.3.6CPE matchmatch criteria
cpe:2.3:a:oracle:fusion_middleware:10.3.6:*:*:*:*:*:*:*
11.1.2.3.0CPE matchmatch criteria
cpe:2.3:a:oracle:fusion_middleware:11.1.2.3.0:*:*:*:*:*:*:*

CVSS Data

CVSS version used by this source: 2.0

5.0MEDIUM

AV:N/AC:L/Au:N/C:P/I:N/A:N

Confidentiality Impact
PARTIAL
Integrity Impact
NONE
Availability Impact
NONE
Access Vector
NETWORK
Access Complexity
LOW
Authentication
NONE
Exploitability Score
10.0
Impact Score
2.9
CvssVersion
2.0

Exploit Intelligence

EPSS Score
32.44%
Probability of exploitation in next 30 days
EPSS Percentile
98.2%
Percentile rank of EPSS score among Peer Group
As of 2026-07-27
Model: v2026.06.15
Nuclei: CVE-2013-3827 · Jun 30, 2021
ExploitDB: EDB-38802 · Oct 15, 2013
This CVE's current EPSS score of 0.3244 is in the 98th percentile among its peer group of 23,723 CVEs.

Social Chatter

No social media mentions found for this CVE.

The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.4 GitHub mentions.

Media Mentions

The average CVE in this peer group has 0.0 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.

Remediation

Patch Available

Vendor Patches (5)

mavenpatch availablevia ghsa
Product: org.glassfish:javax.facesFixed in: 2.1.19
redhatpatch availablevia redhat_api
Product: Red Hat JBoss Data Grid 6.2
View patch
oraclevendor investigatingvia nvd_reference
View patch
redhatno patchvia redhat_api
Product: Red Hat JBoss Data Grid 6Fixed in: jsf2
redhatno patchvia redhat_api
Product: Red Hat JBoss Portal 6Fixed in: jsf2

Vendor Advisories (2)

mavenGHSA-q388-j7cw-ff7wmedium

Path Traversal in Eclipse Mojarra

May 17, 2022
redhatCVE-2013-3827Important

JSF2: Multiple Information Disclosure flaws due to unsafe path traversal

Oct 17, 2013

References

rhn.redhat.com / errata/RHSA-2014-0029.html
kb.cert.org / vuls/id/526012
US Government Resource
oracle.com / technetwork/topics/security/cpuoct2013-1899837.html
Vendor Advisory
securityfocus.com / bid/63052
securitytracker.com / id/1029190