Eclipse
Eclipse Glassfish: vulnerabilidades y CVE
Eclipse Glassfish tiene 13 vulnerabilidades publicadas, 3 de ellas en los últimos 12 meses. 4 son críticas y 0 figuran en el catálogo de explotación activa de CISA.
CVE13
Últimos 12 meses3
Críticas4
Explotadas activamente0
Todas las vulnerabilidades en el catálogo →⭐ Seguir esta tecnología
Últimas vulnerabilidades
| CVE | Severidad | EPSS | Explotación activa | Publicada | Descripción |
|---|---|---|---|---|---|
| CVE-2026-12605 | Crítica (9.6) | 0.43% | — | 6 ago 2026 | In Eclipse GlassFish versions 8.0.x before 8.0.4, CSRF + SSRF in DownloadServlet ContentSources leaks the admin `gfresttoken` to attacker-controlled host if the victim is authenticated into the Admin Console -\> full… |
| CVE-2026-2587 | Crítica (9.6) | 0.67% | — | 19 may 2026 | A critical Remote Code Execution (RCE) vulnerability was identified in the server-side template rendering mechanism used by the Glassfish gadget handler. The application processes .xml files and evaluates user-supplied… |
| CVE-2026-2586 | Crítica (9.1) | 0.83% | — | 19 may 2026 | An authenticated Remote Code Execution (RCE) vulnerability was identified in GlassFish's Administration Console. A user with access to the panel can send crafted requests that allow the execution of arbitrary operating… |
| CVE-2024-9408 | Alta (8.9) | 0.29% | — | 16 jul 2025 | In Eclipse GlassFish since version 6.2.5 it is possible to perform a Server Side Request Forgery attack in specific endpoints. |
| CVE-2024-9343 | Media (6.1) | 0.22% | — | 16 jul 2025 | In Eclipse GlassFish version 7.0.15 is possible to perform Stored Cross-site scripting attacks in the Administration Console. |
| CVE-2024-9342 | Media (6.3) | 0.41% | — | 16 jul 2025 | In Eclipse GlassFish versions before 8.0.3 it is possible to perform Login Brute Force attacks as there is no limitation in the number of failed login attempts. GlassFish 8.0.3 adds automatic attack protection… |
| CVE-2024-10032 | Media (6.1) | 0.21% | — | 16 jul 2025 | In Eclipse GlassFish version 7.0.15 is possible to perform Stored Cross-site scripting attacks in the Administration Console. |
| CVE-2024-10031 | Media (5.8) | 0.16% | — | 16 jul 2025 | In Eclipse GlassFish version 7.0.15 is possible to perform Stored Cross-site Scripting attacks by modifying the configuration file in the underlying operating system. |
| CVE-2024-10029 | Media (4.5) | 0.20% | — | 16 jul 2025 | In Eclipse GlassFish version 7.0.15 is possible to perform Reflected Cross-site scripting attacks in the Administration Console. |
| CVE-2024-9329 | Media (6.9) | 0.72% | — | 30 sept 2024 | In Eclipse Glassfish versions before 7.0.17, The Host HTTP parameter could cause the web application to redirect to the specified URL, when the requested endpoint is '/management/domain'. By modifying the URL value to a… |
| CVE-2024-8646 | Media (6.1) | 0.39% | — | 11 sept 2024 | In Eclipse Glassfish versions prior to 7.0.10, a URL redirection vulnerability to untrusted sites existed. This vulnerability is caused by the vulnerability (CVE-2023-41080) in the Apache code included in GlassFish.… |
| CVE-2023-5763 | Crítica (9.8) | 0.65% | — | 3 nov 2023 | In Eclipse Glassfish 5 or 6, running with old versions of JDK (lower than 6u211, or < 7u201, or < 8u191), allows remote attackers to load malicious code on the server via access to insecure ORB listeners. |
| CVE-2022-2712 | Alta (7.5) | 0.94% | — | 27 ene 2023 | In Eclipse GlassFish versions 5.1.0 to 6.2.5, there is a vulnerability in relative path traversal because it does not filter request path starting with './'. Successful exploitation could allow an remote unauthenticated… |
🎯 Cómo se explota (técnicas ATT&CK)
Número de CVE de esta tecnología asignadas a cada técnica de explotación o de impacto principal.