Rechercher
Contactez-nous Suivez-nous sur Twitter En francais English Language
 

Freely subscribe to our NEWSLETTER

Newsletter FR

Newsletter EN

Vulnérabilités

Unsubscribe

Vigil@nce - Oracle GlassFish Server: Authentication bypass via the administration console

May 2011 by Vigil@nce

This bulletin was written by Vigil@nce : http://vigilance.fr/

SYNTHESIS OF THE VULNERABILITY

A remote attacker can bypass authentication of the administration
console in order to obtain sensitive data.

Severity: 2/4

Creation date: 12/05/2011

IMPACTED PRODUCTS
- Oracle GlassFish Enterprise Server

DESCRIPTION OF THE VULNERABILITY

The administration console of Sun GlassFish Enterprise Server and
Oracle GlassFish Server listens on port 4848/tcp.

However, this service does not correctly validate HTTP TRACE
queries. The query is then processed with no authentication.

A remote attacker can therefore bypass authentication of the
administration console in order to obtain sensitive data.

ACCESS TO THE COMPLETE VIGIL@NCE BULLETIN

http://vigilance.fr/vulnerability/Oracle-GlassFish-Server-Authentication-bypass-via-the-administration-console-10647


See previous articles

    

See next articles


Your podcast Here

New, you can have your Podcast here. Contact us for more information ask:
Marc Brami
Phone: +33 1 40 92 05 55
Mail: ipsimp@free.fr

All new podcasts