Oracle GlassFish Server v2UR2

CPE Details

Oracle GlassFish Server v2UR2
2
2011-12-30
20h16 +00:00
2012-02-10
18h52 +00:00
Alerte pour un CPE
Stay informed of any changes for a specific CPE.
Notifications manage

CPE Name: cpe:2.3:a:oracle:glassfish_server:2:ur2:*:*:*:*:*:*

Informations

Vendor

oracle

Product

glassfish_server

Version

2

Update

ur2

Related CVE

Open and find in CVE List

CVE ID Published Description Score Severity
CVE-2021-3314 2021-06-25 13h16 +00:00 Oracle GlassFish Server 3.1.2.18 and below allows /common/logViewer/logViewer.jsf XSS. A malicious user can cause an administrator user to supply dangerous content to the vulnerable page, which is then reflected back to the user and executed by the web browser. The most common mechanism for delivering malicious content is to include it as a parameter in a URL that is posted publicly or e-mailed directly to victims. NOTE: This vulnerability only affects products that are no longer supported by the maintainer
6.1
Medium
CVE-2011-5035 2011-12-30 00h00 +00:00 Oracle Glassfish 2.1.1, 3.0.1, and 3.1.1, as used in Communications Server 2.0, Sun Java System Application Server 8.1 and 8.2, and possibly other products, computes hash values for form parameters without restricting the ability to trigger hash collisions predictably, which allows remote attackers to cause a denial of service (CPU consumption) by sending many crafted parameters, aka Oracle security ticket S0104869.
5