CVE-2017-1000029
Oracle GlassFish Server Open Source Edition 3.0.1 - Local File Inclusion
Record summary
CVE-2017-1000029 has a selected CVSS score of 7.5 (high); EIP currently links 1 Nuclei template.
Description
Oracle, GlassFish Server Open Source Edition 3.0.1 (build 22) is vulnerable to Local File Inclusion vulnerability, that makes it possible to include arbitrary files on the server, this vulnerability can be exploited without any prior authentication.
Exploitation context
Available material
- Nuclei templates
- 1
Nuclei templates
1ProjectDiscoveryHIGHOracle GlassFish Server Open Source Edition 3.0.1 - Local File InclusionCVSS 7.5
Oracle GlassFish Server Open Source Edition 3.0.1 (build 22) is vulnerable to unauthenticated local file inclusion vulnerabilities that allow remote attackers to request arbitrary files on the server.
Impact
Successful exploitation of this vulnerability could allow an attacker to read sensitive files on the server, potentially leading to unauthorized access or information disclosure.
Remediation
Apply the latest patches and updates provided by Oracle to fix the LFI vulnerability in GlassFish Server.
Source: ProjectDiscovery