Glassfish Server

Vendor:

First CVE: Jun 18, 2008 · Active for 18 years

40
Total CVEs
More Total CVEs than 98% of tracked products
3.6
Avg CVEs / Year
Higher CVE frequency than 85% of tracked products
6.4
Avg CVSS
Higher Avg CVSS than 31% of tracked products
0.0%
KEV Rate
Bottom 1%

Trends Over Time

The number and severity of CVEs published that impact Glassfish Server over time

Volume of CVEsAvg CVSS Base Score
First CVE
Jun 18, 2008
18 years ago
Most Recent CVE
Jun 25, 2021
1,858 days ago

CVE Severity & Scoring

Glassfish Server40 CVEs
All CVEs352,785 CVEs
LowMediumHighCritical
Attack Vector
Local1 (2.5%)
Network23 (57.5%)
Unknown16 (40.0%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low22 (55.0%)
High2 (5.0%)
Unknown16 (40.0%)
User Interaction
None16 (40.0%)
Unknown16 (40.0%)
Required8 (20.0%)
Privileges Required
Low2 (5.0%)
High0 (0.0%)
None22 (55.0%)
Unknown16 (40.0%)

Top CVEs

Signals from CVEs in this product scope (40 CVEs).

40 CVEs · Highest risk first

CVEPublishedCVSSRiskKEVExploit
Oracle, GlassFish Server Open Source Edition 4.1 is vulnerable to both authenticated and unauthenticated Directory Traversal vulnerability, that can be exploited by issuing a speci
Jul 17, 20177.591NOYES
Unspecified vulnerability in Oracle Sun GlassFish Enterprise Server 2.1, 2.1.1, and 3.0.1, and Sun Java System Application Server 9.1, allows remote attackers to affect confidentia
Apr 20, 201110.081NOYES
Oracle Glassfish 2.1.1, 3.0.1, and 3.1.1, as used in Communications Server 2.0, Sun Java System Application Server 8.1 and 8.2, and possibly other products, computes hash values fo
Dec 30, 20115.075NOYES
Unspecified vulnerability in the Java Runtime Environment (JRE) in Oracle Java SE 7 update 4 and earlier and 6 update 32 and earlier, and the GlassFish Enterprise Server component
May 3, 20125.834NOYES
Oracle, GlassFish Server Open Source Edition 3.0.1 (build 22) is vulnerable to Local File Inclusion vulnerability, that makes it possible to include arbitrary files on the server,
Jul 17, 20177.533NOYES
Unspecified vulnerability in the Oracle GlassFish Server component in Oracle Fusion Middleware 3.0.1 and 3.1.2 allows remote attackers to affect confidentiality, integrity, and ava
Jul 21, 20169.833NONO
Unspecified vulnerability in the GlassFish Enterprise Server component in Oracle Sun Products Suite GlassFish Enterprise Server 3.1.1 allows remote attackers to affect confidential
May 3, 20126.833NOYES
The demo feature in Oracle GlassFish Open Source Edition 5.0 has TCP port 7676 open by default with a password of admin for the admin account. This allows remote attackers to obtai
Jul 16, 20189.830NONO
Heap-based buffer overflow in Mozilla Network Security Services (NSS) before 3.19.2.3 and 3.20.x and 3.21.x before 3.21.1, as used in Mozilla Firefox before 45.0 and Firefox ESR 38
Mar 13, 20168.830NONO
Vulnerability in the Oracle GlassFish Server component of Oracle Fusion Middleware (subcomponent: Security). Supported versions that are affected are 2.1.1, 3.0.1 and 3.1.2. Diffic
Jan 27, 20179.028NONO

Exploit Exposure

Signals from CVEs in this product scope (40 CVEs).

CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
3 CVEs
7.5% of CVEs· 97th percentile
Nuclei
2 CVEs
5.0% of CVEs· 97th percentile
ExploitDB
8 CVEs
20.0% of CVEs· 87th percentile

Social Chatter

Signals from CVEs in this product scope (40 CVEs).

Media Mentions

Signals from CVEs in this product scope (40 CVEs).

Top CNAs Publishing CVEs For Glassfish Server

Top CWEs

Versions

VersionCVE CountAvg CVSSAvg EPSSKEVExploits
5.019.84.3%00
4.117.599.5%01
3.1.2186.42.3%00
3.1.155.84.7%02
3.0.1236.68.1%04
3.014.34.4%01
2.1.1166.610.5%03
2.146.118.4%03
2.024.34.6%02
1.014.34.4%01