PT-2011-1542 · Oracle · Oracle Glassfish+1

Publicado

2011-01-19

·

Atualizado

2017-08-17

·

CVE-2010-4438

CVSS v2.0

5.7

Média

VetorAV:L/AC:L/Au:S/C:P/I:P/A:C
Name of the Vulnerable Software and Affected Versions Oracle GlassFish versions 2.1 through 3.0.1 Java System Message Queue version 4.1
Description The issue affects confidentiality, integrity, and availability, and is related to Java Message Service (JMS), allowing local users to exploit it.
Recommendations For Oracle GlassFish versions 2.1 through 3.0.1, consider restricting access to Java Message Service (JMS) until a fix is available. For Java System Message Queue version 4.1, avoid using the JMS functionality in sensitive operations until the issue is resolved. At the moment, there is no information about a newer version that contains a fix for this vulnerability.
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Identificadores relacionados

CVE-2010-4438

Produtos afetados

Java System Message Queue
Oracle Glassfish