Java System Application Server

Vendor:

First CVE: Dec 31, 2004 · Active for 21 years

22
Total CVEs
More Total CVEs than 94% of tracked products
2.4
Avg CVEs / Year
Higher CVE frequency than 74% of tracked products
5.7
Avg CVSS
Higher Avg CVSS than 17% of tracked products
0.0%
KEV Rate
Bottom 1%

Trends Over Time

The number and severity of CVEs published that impact Java System Application Server over time

Volume of CVEsAvg CVSS Base Score
First CVE
Dec 31, 2004
21 years ago
Most Recent CVE
Oct 16, 2012
5,030 days ago

CVE Severity & Scoring

Java System Application Server22 CVEs
All CVEs352,427 CVEs
LowMediumHigh
Attack Vector
Local0 (0.0%)
Network1 (4.5%)
Unknown21 (95.5%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low1 (4.5%)
High0 (0.0%)
Unknown21 (95.5%)
User Interaction
None0 (0.0%)
Unknown21 (95.5%)
Required1 (4.5%)
Privileges Required
Low0 (0.0%)
High0 (0.0%)
None1 (4.5%)
Unknown21 (95.5%)

Top CVEs

Signals from CVEs in this product scope (22 CVEs).

22 CVEs · Highest risk first

CVEPublishedCVSSRiskKEVExploit
Unspecified vulnerability in Oracle Sun GlassFish Enterprise Server 2.1, 2.1.1, and 3.0.1, and Sun Java System Application Server 9.1, allows remote attackers to affect confidentia
Apr 20, 201110.081NOYES
Heap-based buffer overflow in Netscape Network Security Services (NSS) library allows remote attackers to execute arbitrary code via a modified record length field in an SSLv2 clie
Dec 31, 20047.529NONO
Sun Java System Application Server and Web Server 7.0 through 9.0 before 20070710 do not properly process XSLT stylesheets in XSLT transforms in XML signatures, which allows contex
Jul 11, 20079.323NONO
The default configuration of Sun Java System Application Server 7 and 7 2004Q2 enables the HTTP TRACE method, which makes it easier for remote attackers to steal cookies and authen
Jan 25, 20108.122NONO
Cross-site scripting (XSS) vulnerability in configuration/httpListenerEdit.jsf in the GlassFish 2 UR2 b04 webadmin interface in Sun Java System Application Server 9.1_01 build b09d
Nov 28, 20084.322NOYES
Multiple cross-site scripting (XSS) vulnerabilities in the Glassfish webadmin interface in Sun Java System Application Server 9.1_01 allow remote attackers to inject arbitrary web
Jun 18, 20084.322NOYES
Sun Java System Access Manager 7.1, when installed in a Sun Java System Application Server 9.1 container, does not demand authentication after a container restart, which allows rem
Oct 1, 20077.522NONO
Unspecified vulnerability in Sun Java System Access Manager 7.1, when installed in a Sun Java System Application Server 8.x container, allows remote attackers to execute arbitrary
Oct 1, 20076.821NONO
HTTP request smuggling vulnerability in Sun Java System Proxy Server before 20061130, when used with Sun Java System Application Server or Sun Java System Web Server, allows remote
Dec 4, 20066.819NONO
Cross-site scripting (XSS) vulnerability in Sun ONE Web Server 6.0 SP9 and earlier, Java System Web Server 6.1 SP4 and earlier, Sun ONE Application Server 7 Platform and Standard E
May 20, 20066.819NONO

Exploit Exposure

Signals from CVEs in this product scope (22 CVEs).

CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
1 CVE
4.5% of CVEs· 96th percentile
Nuclei
0 CVEs
0.0% of CVEs· Bottom 1%
ExploitDB
3 CVEs
13.6% of CVEs· 89th percentile

Social Chatter

Signals from CVEs in this product scope (22 CVEs).

Media Mentions

Signals from CVEs in this product scope (22 CVEs).

Top CNAs Publishing CVEs For Java System Application Server

Top CWEs

Versions

VersionCVE CountAvg CVSSAvg EPSSKEVExploits
9.1_0214.34.9%01
9.1_0124.34.6%02
9.128.831.9%01
9.0_0.115.01.6%00
9.028.52.2%00
8.257.42.3%00
8.194.82.4%00
7.125.812.3%00
7.085.03.8%00
6.015.02.2%00