An authenticated Remote Code Execution (RCE) vulnerability was identified in GlassFish's Administration Console. A user with access to the panel can send crafted requests that allow the execution of arbitrary operating system commands with the privileges of the application service user. This issue affects Eclipse GlassFish: from 8.0.0 to 8.0.1, fixed in 8.0.2; 7.1.0, fixed in 7.1.1; from 7.0.0 to 7.0.25, fixed in 7.0.26. Impact on versions from 5.1.0 to 6.2.5 is unknown.
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:HEclipse Glassfish
APPEclipse< 8.0.2
Related vulnerabilities
Eclipse GlassFish: CSRF+SSRF w DownloadServlet umożliwia przejęcie domeny
RCE poprzez wstrzyknięcie Expression Language w Eclipse GlassFish
In Eclipse GlassFish since version 6.2.5 it is possible to perform a Server Side Request Forgery attack in spe...
In Eclipse GlassFish version 7.0.15 is possible to perform Reflected Cross-site scripting attacks in the Admin...
In Eclipse GlassFish version 7.0.15 is possible to perform Stored Cross-site scripting attacks in the Administ...