Oracle, GlassFish Server Open Source Edition 4.1 is vulnerable to both authenticated and unauthenticated Directory Traversal vulnerability, that can be exploited by issuing a specially crafted HTTP GET request.
https://github.com/baifdz/Patches
https://github.com/cyberwithcyril/VulhubPenTestingReport
https://github.com/liminghjh/CVE-vulnerability-reproduction
https://www.trustwave.com/Resources/Security-Advisories/Advisories/TWSL2015-016/?fid=6904
https://www.exploit-db.com/exploits/45198/