First published: Fri Jan 27 2017(Updated: )
Vulnerability in the Oracle GlassFish Server component of Oracle Fusion Middleware (subcomponent: Administration). Supported versions that are affected are 3.0.1 and 3.1.2. Easily exploitable vulnerability allows low privileged attacker with logon to the infrastructure where Oracle GlassFish Server executes to compromise Oracle GlassFish Server. Successful attacks of this vulnerability can result in unauthorized read access to a subset of Oracle GlassFish Server accessible data. CVSS v3.0 Base Score 3.3 (Confidentiality impacts).
Credit: secalert_us@oracle.com
Affected Software | Affected Version | How to fix |
---|---|---|
Oracle GlassFish Enterprise Server | =3.0.1 | |
Oracle GlassFish Enterprise Server | =3.1.2 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2017-3239 is considered an easily exploitable vulnerability that can be exploited by low privileged attackers.
To address CVE-2017-3239, users should apply the latest security patches provided by Oracle for GlassFish Server.
CVE-2017-3239 affects Oracle GlassFish Server versions 3.0.1 and 3.1.2.
CVE-2017-3239 can be exploited by low privileged attackers who have logon access to the infrastructure.
CVE-2017-3239 impacts the Administration component of the Oracle GlassFish Server.