Anfälligkeitssuche        Suche in 324607 CVE Beschreibungen
und 145615 Test Beschreibungen,
Zugriff auf 10,000+ Quellverweise.
Tests   CVE   Alle  

Test Kennung:1.3.6.1.4.1.25623.1.0.802624
Kategorie:Web Servers
Titel:Oracle GlassFish Server 3.1.1 Multiple Vulnerabilities (Apr 2012)
Zusammenfassung:Oracle GlassFish Server is prone to multiple; vulnerabilities.
Beschreibung:Summary:
Oracle GlassFish Server is prone to multiple
vulnerabilities.

Vulnerability Insight:
Multiple flaws are due to:

- Input passed via multiple parameters to various scripts is not properly sanitised before being
returned to the user. This can be exploited to execute arbitrary HTML and script code in a user's
browser session in context of an affected site.

- The application allows users to perform certain actions via HTTP requests without performing
proper validity checks to verify the requests.

Vulnerability Impact:
Successful exploitation will allow remote attackers to insert
arbitrary HTML and script code, which will be executed in a user's browser session in the context
of an affected site.

Affected Software/OS:
Oracle GlassFish Server version 3.1.1.

Solution:
Apply the patch from the referenced advisory.

CVSS Score:
6.8

CVSS Vector:
AV:N/AC:M/Au:N/C:P/I:P/A:P

Querverweis: Common Vulnerability Exposure (CVE) ID: CVE-2012-0550
http://www.mandriva.com/security/advisories?name=MDVSA-2013:150
http://www.securitytracker.com/id?1026941
Common Vulnerability Exposure (CVE) ID: CVE-2012-0551
BugTraq ID: 53136
http://www.securityfocus.com/bid/53136
HPdes Security Advisory: HPSBUX02805
http://marc.info/?l=bugtraq&m=134496371727681&w=2
HPdes Security Advisory: SSRT100919
https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A16707
RedHat Security Advisories: RHSA-2012:0734
http://rhn.redhat.com/errata/RHSA-2012-0734.html
RedHat Security Advisories: RHSA-2013:1455
http://rhn.redhat.com/errata/RHSA-2013-1455.html
RedHat Security Advisories: RHSA-2013:1456
http://rhn.redhat.com/errata/RHSA-2013-1456.html
SuSE Security Announcement: SUSE-SU-2012:1231 (Google Search)
http://lists.opensuse.org/opensuse-security-announce/2012-09/msg00032.html
SuSE Security Announcement: SUSE-SU-2012:1265 (Google Search)
http://lists.opensuse.org/opensuse-security-announce/2012-09/msg00035.html
CopyrightCopyright (C) 2012 Greenbone AG

Dies ist nur einer von 145615 Anfälligkeitstests in unserem Testpaket. Finden Sie mehr über unsere vollständigen Sicherheitsüberprüfungen heraus.

Um einen gratis Test für diese Anfälligkeit auf Ihrem System durchlaufen zu lassen, registrieren Sie sich bitte unten.




© 1998-2025 E-Soft Inc. Alle Rechte vorbehalten.