CVE-2017-1000030: Critical severity glassfish vulnerability
Oracle, GlassFish Server Open Source Edition 3.0.1 (build 22) is vulnerable to Java Key Store Password Disclosure vulnerability, that makes it possible to provide an unauthenticated attacker plain text password of administrative user and grant access to the web-based administration interface.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2017-1000030?
CVE-2017-1000030 is considered a critical vulnerability due to the potential for unauthorized access to the administrative interface.
How do I fix CVE-2017-1000030?
To fix CVE-2017-1000030, it is recommended to apply the latest updates and patches provided by Oracle for GlassFish Server.
What type of attack does CVE-2017-1000030 enable?
CVE-2017-1000030 enables unauthenticated attackers to disclose plaintext passwords of administrative users.
Which version of GlassFish Server is affected by CVE-2017-1000030?
CVE-2017-1000030 specifically affects Oracle GlassFish Server Open Source Edition 3.0.1.
Can CVE-2017-1000030 be exploited remotely?
Yes, CVE-2017-1000030 can be exploited remotely by attackers to gain unauthorized access.