Summary
The host is running Oracle GlassFish Server and is prone to security bypass vulnerability.
Impact
Successful exploitation could allow local attackers to access sensitive data on the server without being authenticated, by making 'TRACE' requests against the Administration Console.
Impact Level: System/Application
Solution
Upgrade to Oracle GlassFish 3.1 or later,
For updated refer, http://glassfish.java.net/downloads/3.1-final.html
Insight
The flaw is due to an error in Administration Console, when handling HTTP requests using the 'TRACE' method. A remote unauthenticated attacker can get access to the content of restricted pages in the Administration Console.
and also attacker can create a new Glassfish administrator.
Affected
Oracle GlassFish version 3.0.1 and prior.
References
Severity
Classification
-
CVE CVE-2011-1511 -
CVSS Base Score: 6.4
AV:N/AC:L/Au:N/C:P/I:P/A:N
Related Vulnerabilities