Skip to main content

Vendor/product archive

eclipse / glassfish CVEs

Beta · best-effort

12 CVEs tagged to eclipse / glassfish2 Critical, 1 High, 9 Medium, 0 Low, 0 Unrated.

CVE-2026-2587

Published May 19, 2026

A critical Remote Code Execution (RCE) vulnerability was identified in the server-side template rendering mechanism used by the Glassfish gadget handler. The application processes…

CVSS 9.6 · Critical
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2026-2586

Published May 19, 2026

An authenticated Remote Code Execution (RCE) vulnerability was identified in GlassFish's Administration Console. A user with access to the panel can send crafted requests that all…

CVSS 9.1 · Critical
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2024-9408

Published Jul 16, 2025

In Eclipse GlassFish since version 6.2.5 it is possible to perform a Server Side Request Forgery attack in specific endpoints.

CVSS 8.9 · High
Vendor/product tagsBeta · best-effort

CVE-2024-9343

Published Jul 16, 2025

In Eclipse GlassFish version 7.0.15 is possible to perform Stored Cross-site scripting attacks in the Administration Console.

CVSS 6.1 · Medium
Vendor/product tagsBeta · best-effort

CVE-2024-9342

Published Jul 16, 2025

In Eclipse GlassFish versions before 8.0.3 it is possible to perform Login Brute Force attacks as there is no limitation in the number of failed login attempts. GlassFish 8.0.3 ad…

CVSS 6.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2024-10032

Published Jul 16, 2025

In Eclipse GlassFish version 7.0.15 is possible to perform Stored Cross-site scripting attacks in the Administration Console.

CVSS 6.1 · Medium
Vendor/product tagsBeta · best-effort

CVE-2024-10031

Published Jul 16, 2025

In Eclipse GlassFish version 7.0.15 is possible to perform Stored Cross-site Scripting attacks by modifying the configuration file in the underlying operating system.

CVSS 5.8 · Medium
Vendor/product tagsBeta · best-effort

CVE-2024-10029

Published Jul 16, 2025

In Eclipse GlassFish version 7.0.15 is possible to perform Reflected Cross-site scripting attacks in the Administration Console.

CVSS 4.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2024-9329

Published Sep 30, 2024

In Eclipse Glassfish versions before 7.0.17, The Host HTTP parameter could cause the web application to redirect to the specified URL, when the requested endpoint is '/management/…

CVSS 6.9 · Medium
Vendor/product tagsBeta · best-effort

CVE-2024-8646

Published Sep 11, 2024

In Eclipse Glassfish versions prior to 7.0.10, a URL redirection vulnerability to untrusted sites existed. This vulnerability is caused by the vulnerability (CVE-2023-41080) in th…

CVSS 6.1 · Medium
Vendor/product tagsBeta · best-effort

CVE-2023-5763

Published Nov 3, 2023

In Eclipse Glassfish 5 or 6, running with old versions of JDK (lower than 6u211, or < 7u201, or < 8u191), allows remote attackers to load malicious code on the server via access t…

CVSS 6.8 · Medium
Vendor/product tagsBeta · best-effort

CVE-2022-2712

Published Jan 27, 2023

In Eclipse GlassFish versions 5.1.0 to 6.2.5, there is a vulnerability in relative path traversal because it does not filter request path starting with './'. Successful exploitati…

CVSS 6.5 · Medium
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort
Showing 1-12 of 12 CVEsPage 1 of 1