PT-2011-1542 · Oracle · Oracle Glassfish+1
Published
2011-01-19
·
Updated
2017-08-17
·
CVE-2010-4438
CVSS v2.0
5.7
Medium
| Vector | AV:L/AC:L/Au:S/C:P/I:P/A:C |
Name of the Vulnerable Software and Affected Versions
Oracle GlassFish versions 2.1 through 3.0.1
Java System Message Queue version 4.1
Description
The issue affects confidentiality, integrity, and availability, and is related to Java Message Service (JMS), allowing local users to exploit it.
Recommendations
For Oracle GlassFish versions 2.1 through 3.0.1, consider restricting access to Java Message Service (JMS) until a fix is available.
For Java System Message Queue version 4.1, avoid using the JMS functionality in sensitive operations until the issue is resolved.
At the moment, there is no information about a newer version that contains a fix for this vulnerability.
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Java System Message Queue
Oracle Glassfish