PT-2018-12439 · Oracle · Oracle Glassfish Open Source Edition

Glassfishrobot

·

Published

2018-07-16

·

Updated

2019-05-20

·

CVE-2018-14324

CVSS v2.0

10

Critical

VectorAV:N/AC:L/Au:N/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions Oracle GlassFish Open Source Edition version 5.0
Description The issue allows remote attackers to obtain potentially sensitive information, perform database operations, or manipulate the demo via a JMX RMI session. This is due to the demo feature having TCP port 7676 open by default with a password of admin for the admin account.
Recommendations For Oracle GlassFish Open Source Edition version 5.0, change the default password of the admin account to prevent unauthorized access. Consider restricting access to TCP port 7676 to minimize the risk of exploitation. As a temporary workaround, consider disabling the demo feature until a more secure configuration can be implemented.

Fix

Using Hardcoded Credentials

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2018-14324

Affected Products

Oracle Glassfish Open Source Edition