CVE-2017-1000029
HIGH 7.5EPSS 8.3%
Oracle, GlassFish Server Open Source Edition 3.0.1 (build 22) is vulnerable to Local File Inclusion vulnerability, that makes it possible to include arbitrary files on the server, this vulnerability can be exploited without any prior authentication.
- CVSS v3.0
- 7.5 HIGH
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N - CVSS v2.0
- 5.0 MEDIUM
AV:N/AC:L/Au:N/C:P/I:N/A:N - EPSS
- 8.35% chance of exploitation in the next 30 days, 95th percentile
- Nuclei
- high · CWE-200
- Published
- 2017-07-13
- Updated
- 2024-08-05