Oracle GlassFish Server Path Traversal

high Nessus Plugin ID 110192


The remote web application server is affected by a path traversal vulnerability.


The instance of Oracle GlassFish Server running on the remote host is affected by an authenticated and unauthenticated path traversal vulnerability. Remote attacker can exploit this issue, via a specially crafted HTTP request, to access arbitrary files on the remote host.


Contact to vendor for patch options.

See Also

Plugin Details

Severity: High

ID: 110192

File Name: glassfish4_remote_file_disclosure.nasl

Version: 1.4

Type: remote

Family: CGI abuses

Published: 5/30/2018

Updated: 6/14/2018

Supported Sensors: Nessus

Risk Information


Risk Factor: Medium

Score: 4.4


Risk Factor: Medium

Base Score: 5

Temporal Score: 4.8

Vector: CVSS2#AV:N/AC:L/Au:N/C:P/I:N/A:N


Risk Factor: High

Base Score: 7.5

Temporal Score: 7.3

Vector: CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N

Temporal Vector: CVSS:3.0/E:F/RL:U/RC:X

Vulnerability Information

CPE: cpe:/a:oracle:glassfish_server

Required KB Items: www/glassfish, www/glassfish/console

Exploit Available: true

Exploit Ease: Exploits are available

Exploited by Nessus: true

Vulnerability Publication Date: 7/17/2017

Reference Information

CVE: CVE-2017-1000028