PT-2018-12439 · Oracle · Oracle Glassfish Open Source Edition
Glassfishrobot
·
Publicado
2018-07-16
·
Atualizado
2019-05-20
·
CVE-2018-14324
CVSS v2.0
10
Crítica
| Vetor | AV:N/AC:L/Au:N/C:C/I:C/A:C |
Name of the Vulnerable Software and Affected Versions
Oracle GlassFish Open Source Edition version 5.0
Description
The issue allows remote attackers to obtain potentially sensitive information, perform database operations, or manipulate the demo via a JMX RMI session. This is due to the demo feature having TCP port 7676 open by default with a password of
admin for the admin account.Recommendations
For Oracle GlassFish Open Source Edition version 5.0, change the default password of the
admin account to prevent unauthorized access. Consider restricting access to TCP port 7676 to minimize the risk of exploitation. As a temporary workaround, consider disabling the demo feature until a more secure configuration can be implemented.Correção
Using Hardcoded Credentials
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾
Enumeração de Fraquezas
Identificadores relacionados
Produtos afetados
Oracle Glassfish Open Source Edition