CVE-2017-1000028: Path Traversal
Oracle, GlassFish Server Open Source Edition 4.1 is vulnerable to both authenticated and unauthenticated Directory Traversal vulnerability, that can be exploited by issuing a specially crafted HTTP GET request.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2017-1000028?
CVE-2017-1000028 is considered to have a high severity due to its potential for unauthorized access and data exposure.
How do I fix CVE-2017-1000028?
To fix CVE-2017-1000028, you should apply the latest security patches provided by Oracle for GlassFish Server Open Source Edition 4.1.
Can CVE-2017-1000028 be exploited remotely?
Yes, CVE-2017-1000028 can be exploited remotely through specially crafted HTTP GET requests.
What are the potential impacts of CVE-2017-1000028?
The potential impacts of CVE-2017-1000028 include unauthorized access to sensitive files and directories on the server.
Is CVE-2017-1000028 applicable only to authenticated users?
No, CVE-2017-1000028 can be exploited by both authenticated and unauthenticated users.