CVE-2026-12605
- EPSS 0.24%
- Veröffentlicht 06.08.2026 13:18:05
- Zuletzt bearbeitet 10.08.2026 14:54:39
In Eclipse GlassFish versions 8.0.x before 8.0.4, CSRF + SSRF in DownloadServlet ContentSources leaks the admin `gfresttoken` to attacker-controlled host if the victim is authenticated into the Admin Console -\> full unauthenticated takeover of Eclip...
CVE-2026-12606
- EPSS 0.27%
- Veröffentlicht 14.07.2026 08:28:17
- Zuletzt bearbeitet 27.07.2026 13:16:51
Eclipse Grizzly in versions before 5.0.2, cannot properly parse the trailer section in malformed trailer header's line, which can be leveraged to perform HTTP request smuggling. Grizzly 5.0.1 supports system properties that enable the behavior that f...
CVE-2026-2586
- EPSS 0.84%
- Veröffentlicht 19.05.2026 14:12:06
- Zuletzt bearbeitet 24.07.2026 12:10:00
An authenticated Remote Code Execution (RCE) vulnerability was identified in GlassFish's Administration Console. A user with access to the panel can send crafted requests that allow the execution of arbitrary operating system commands with the privil...
CVE-2026-2587
- EPSS 0.65%
- Veröffentlicht 19.05.2026 14:03:18
- Zuletzt bearbeitet 24.07.2026 12:10:00
A critical Remote Code Execution (RCE) vulnerability was identified in the server-side template rendering mechanism used by the Glassfish gadget handler. The application processes .xml files and evaluates user-supplied values within a context where E...
CVE-2024-10031
- EPSS 0.16%
- Veröffentlicht 16.07.2025 11:15:23
- Zuletzt bearbeitet 16.07.2025 19:56:10
In Eclipse GlassFish version 7.0.15 is possible to perform Stored Cross-site Scripting attacks by modifying the configuration file in the underlying operating system.
CVE-2024-10032
- EPSS 0.21%
- Veröffentlicht 16.07.2025 11:15:23
- Zuletzt bearbeitet 16.07.2025 19:55:57
In Eclipse GlassFish version 7.0.15 is possible to perform Stored Cross-site scripting attacks in the Administration Console.
CVE-2024-9408
- EPSS 0.29%
- Veröffentlicht 16.07.2025 11:15:03
- Zuletzt bearbeitet 16.07.2025 19:54:17
In Eclipse GlassFish since version 6.2.5 it is possible to perform a Server Side Request Forgery attack in specific endpoints.
CVE-2024-10029
- EPSS 0.2%
- Veröffentlicht 16.07.2025 10:55:35
- Zuletzt bearbeitet 16.07.2025 19:56:18
In Eclipse GlassFish version 7.0.15 is possible to perform Reflected Cross-site scripting attacks in the Administration Console.
CVE-2024-9343
- EPSS 0.22%
- Veröffentlicht 16.07.2025 10:47:55
- Zuletzt bearbeitet 16.07.2025 19:55:32
In Eclipse GlassFish version 7.0.15 is possible to perform Stored Cross-site scripting attacks in the Administration Console.
CVE-2024-9342
- EPSS 0.41%
- Veröffentlicht 16.07.2025 10:14:28
- Zuletzt bearbeitet 16.07.2025 19:55:45
In Eclipse GlassFish version 7.0.16 or earlier it is possible to perform Login Brute Force attacks as there is no limitation in the number of failed login attempts.