Glassfish Server
Vendor:
First CVE: Jun 18, 2008 · Active for 18 years
40
Total CVEs
More Total CVEs than 98% of tracked products
3.6
Avg CVEs / Year
Higher CVE frequency than 85% of tracked products
6.4
Avg CVSS
Higher Avg CVSS than 31% of tracked products
0.0%
KEV Rate
Bottom 1%
Trends Over Time
The number and severity of CVEs published that impact Glassfish Server over time
Volume of CVEsAvg CVSS Base Score
First CVE
Jun 18, 2008
18 years ago
Most Recent CVE
Jun 25, 2021
1,858 days ago
CVE Severity & Scoring
Glassfish Server40 CVEs
10%
50%
28%
13%
All CVEs352,785 CVEs
45%
40%
11%
LowMediumHighCritical
Attack Vector
Local1 (2.5%)
Network23 (57.5%)
Unknown16 (40.0%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low22 (55.0%)
High2 (5.0%)
Unknown16 (40.0%)
User Interaction
None16 (40.0%)
Unknown16 (40.0%)
Required8 (20.0%)
Privileges Required
Low2 (5.0%)
High0 (0.0%)
None22 (55.0%)
Unknown16 (40.0%)
Top CVEs
Signals from CVEs in this product scope (40 CVEs).
40 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2017-1000028HIGH Oracle, GlassFish Server Open Source Edition 4.1 is vulnerable to both authenticated and unauthenticated Directory Traversal vulnerability, that can be exploited by issuing a speci | Jul 17, 2017 | 7.5 | 91 | NO | YES |
CVE-2011-0807HIGH Unspecified vulnerability in Oracle Sun GlassFish Enterprise Server 2.1, 2.1.1, and 3.0.1, and Sun Java System Application Server 9.1, allows remote attackers to affect confidentia | Apr 20, 2011 | 10.0 | 81 | NO | YES |
CVE-2011-5035MEDIUM Oracle Glassfish 2.1.1, 3.0.1, and 3.1.1, as used in Communications Server 2.0, Sun Java System Application Server 8.1 and 8.2, and possibly other products, computes hash values fo | Dec 30, 2011 | 5.0 | 75 | NO | YES |
CVE-2012-0551MEDIUM Unspecified vulnerability in the Java Runtime Environment (JRE) in Oracle Java SE 7 update 4 and earlier and 6 update 32 and earlier, and the GlassFish Enterprise Server component | May 3, 2012 | 5.8 | 34 | NO | YES |
CVE-2017-1000029HIGH Oracle, GlassFish Server Open Source Edition 3.0.1 (build 22) is vulnerable to Local File Inclusion vulnerability, that makes it possible to include arbitrary files on the server, | Jul 17, 2017 | 7.5 | 33 | NO | YES |
CVE-2016-3607CRITICAL Unspecified vulnerability in the Oracle GlassFish Server component in Oracle Fusion Middleware 3.0.1 and 3.1.2 allows remote attackers to affect confidentiality, integrity, and ava | Jul 21, 2016 | 9.8 | 33 | NO | NO |
CVE-2012-0550MEDIUM Unspecified vulnerability in the GlassFish Enterprise Server component in Oracle Sun Products Suite GlassFish Enterprise Server 3.1.1 allows remote attackers to affect confidential | May 3, 2012 | 6.8 | 33 | NO | YES |
CVE-2018-14324CRITICAL The demo feature in Oracle GlassFish Open Source Edition 5.0 has TCP port 7676 open by default with a password of admin for the admin account. This allows remote attackers to obtai | Jul 16, 2018 | 9.8 | 30 | NO | NO |
CVE-2016-1950HIGH Heap-based buffer overflow in Mozilla Network Security Services (NSS) before 3.19.2.3 and 3.20.x and 3.21.x before 3.21.1, as used in Mozilla Firefox before 45.0 and Firefox ESR 38 | Mar 13, 2016 | 8.8 | 30 | NO | NO |
CVE-2016-5528CRITICAL Vulnerability in the Oracle GlassFish Server component of Oracle Fusion Middleware (subcomponent: Security). Supported versions that are affected are 2.1.1, 3.0.1 and 3.1.2. Diffic | Jan 27, 2017 | 9.0 | 28 | NO | NO |
Exploit Exposure
Signals from CVEs in this product scope (40 CVEs).
CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
3 CVEs
7.5% of CVEs· 97th percentile
Nuclei
2 CVEs
5.0% of CVEs· 97th percentile
ExploitDB
8 CVEs
20.0% of CVEs· 87th percentile
Social Chatter
Signals from CVEs in this product scope (40 CVEs).
Media Mentions
Signals from CVEs in this product scope (40 CVEs).
Top CNAs Publishing CVEs For Glassfish Server
Top CWEs
Versions
| Version | CVE Count | Avg CVSS | Avg EPSS | KEV | Exploits |
|---|---|---|---|---|---|
| 5.0 | 1 | 9.8 | 4.3% | 0 | 0 |
| 4.1 | 1 | 7.5 | 99.5% | 0 | 1 |
| 3.1.2 | 18 | 6.4 | 2.3% | 0 | 0 |
| 3.1.1 | 5 | 5.8 | 4.7% | 0 | 2 |
| 3.0.1 | 23 | 6.6 | 8.1% | 0 | 4 |
| 3.0 | 1 | 4.3 | 4.4% | 0 | 1 |
| 2.1.1 | 16 | 6.6 | 10.5% | 0 | 3 |
| 2.1 | 4 | 6.1 | 18.4% | 0 | 3 |
| 2.0 | 2 | 4.3 | 4.6% | 0 | 2 |
| 1.0 | 1 | 4.3 | 4.4% | 0 | 1 |