PT-2018-12439 · Oracle · Oracle Glassfish Open Source Edition
Glassfishrobot
·
Published
2018-07-16
·
Updated
2019-05-20
·
CVE-2018-14324
CVSS v2.0
10
Critical
| Vector | AV:N/AC:L/Au:N/C:C/I:C/A:C |
Name of the Vulnerable Software and Affected Versions
Oracle GlassFish Open Source Edition version 5.0
Description
The issue allows remote attackers to obtain potentially sensitive information, perform database operations, or manipulate the demo via a JMX RMI session. This is due to the demo feature having TCP port 7676 open by default with a password of
admin for the admin account.Recommendations
For Oracle GlassFish Open Source Edition version 5.0, change the default password of the
admin account to prevent unauthorized access. Consider restricting access to TCP port 7676 to minimize the risk of exploitation. As a temporary workaround, consider disabling the demo feature until a more secure configuration can be implemented.Fix
Using Hardcoded Credentials
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Oracle Glassfish Open Source Edition