CORE IMPACT v12 - Exploits Update (Wed Dec 14 2011)
Oracle GlassFish Server Administration Console Authentication Bypass Remote Code Execution Exploit Update
Exploits/Remote Code Execution [Solaris]
Wed Dec 14 2011
The Administration Console of Oracle GlassFish Server is prone to an authentication bypass vulnerability, which can be achieved by performing HTTP TRACE requests. A remote unauthenticated attacker can exploit this in order to execute arbitrary code on the vulnerable server. This update adds support for Solaris platforms.
Exploits Vulnerabiltiy: CVE-2011-1511











