Core Security
info@coresecurity.com  | +1.617.399.6980 | Contact Us   Core Blog Core Blog Twitter LinkedIn youtube
SHARE

CORE IMPACT v12 - Exploits Update (Wed Dec 14 2011)

Oracle GlassFish Server Administration Console Authentication Bypass Remote Code Execution Exploit Update

Exploits/Remote Code Execution  [Solaris]




Wed Dec 14 2011
The Administration Console of Oracle GlassFish Server is prone to an authentication bypass vulnerability, which can be achieved by performing HTTP TRACE requests. A remote unauthenticated attacker can exploit this in order to execute arbitrary code on the vulnerable server. This update adds support for Solaris platforms.

Exploits Vulnerabiltiy: CVE-2011-1511



< Back to Product Updates