Record summary

CVE-2017-1000029 has a selected CVSS score of 7.5 (high); EIP currently links 1 Nuclei template.

Description

Oracle, GlassFish Server Open Source Edition 3.0.1 (build 22) is vulnerable to Local File Inclusion vulnerability, that makes it possible to include arbitrary files on the server, this vulnerability can be exploited without any prior authentication.

Description source: CVE List

Exploitation context

Available material

Nuclei templates
1

Nuclei templates

1
ProjectDiscoveryHIGHOracle GlassFish Server Open Source Edition 3.0.1 - Local File InclusionCVSS 7.5

Oracle GlassFish Server Open Source Edition 3.0.1 (build 22) is vulnerable to unauthenticated local file inclusion vulnerabilities that allow remote attackers to request arbitrary files on the server.

Impact

Successful exploitation of this vulnerability could allow an attacker to read sensitive files on the server, potentially leading to unauthorized access or information disclosure.

Remediation

Apply the latest patches and updates provided by Oracle to fix the LFI vulnerability in GlassFish Server.

WeaknessesCWE-200
Authors0x_Akoko
Template tagscvecve2017glassfishoraclelfivuln
CVSS vector: CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
CPE: cpe:2.3:a:oracle:glassfish_server:3.0.1:*:*:*:open_source:*:*:*
Shodan: cpe:"cpe:2.3:a:oracle:glassfish_server"

Source: ProjectDiscovery

References

2