Rechercher
Contactez-nous Suivez-nous sur Twitter En francais English Language
 

Freely subscribe to our NEWSLETTER

Newsletter FR

Newsletter EN

Vulnérabilités

Unsubscribe

Vigil@nce: GlassFish Enterprise Server, several vulnerabilities of January 2012

February 2012 by Vigil@nce

This bulletin was written by Vigil@nce : http://vigilance.fr/offer

SYNTHESIS OF THE VULNERABILITY

Several vulnerabilities of GlassFish Enterprise Server are
corrected by the CPU of January 2012.

 Severity: 2/4
 Creation date: 18/01/2012

IMPACTED PRODUCTS

 Oracle GlassFish Enterprise Server

DESCRIPTION OF THE VULNERABILITY

A Critical Patch Update corrects several vulnerabilities of
GlassFish Enterprise Server.

An attacker can post HTTP data generating storage collisions, in
order to overload a remote web server. [severity:2/4;
CVE-2011-5035]

An attacker can use a vulnerability of Web Container, in order to
create a denial of service. [severity:2/4; BID-51484,
CVE-2012-0104]

An attacker can use a vulnerability of Administration, in order to
obtain information, to alter information, or to create a denial of
service. [severity:2/4; BID-51485, CVE-2012-0081]

An attacker can use a vulnerability of Administration, in order to
obtain information. [severity:1/4; BID-51497, CVE-2011-3564]

ACCESS TO THE COMPLETE VIGIL@NCE BULLETIN

http://vigilance.fr/vulnerability/GlassFish-Enterprise-Server-several-vulnerabilities-of-January-2012-11298


See previous articles

    

See next articles


Your podcast Here

New, you can have your Podcast here. Contact us for more information ask:
Marc Brami
Phone: +33 1 40 92 05 55
Mail: ipsimp@free.fr

All new podcasts