Search
Contactez-nous Suivez-nous sur Twitter En francais English Language
 

Freely subscribe to our NEWSLETTER

Newsletter FR

Newsletter EN

Vulnérabilités

Unsubscribe











Vigil@nce: GlassFish Enterprise Server, several vulnerabilities of January 2012

February 2012 by Vigil@nce

This bulletin was written by Vigil@nce : http://vigilance.fr/offer

SYNTHESIS OF THE VULNERABILITY

Several vulnerabilities of GlassFish Enterprise Server are corrected by the CPU of January 2012.

- Severity: 2/4
- Creation date: 18/01/2012

IMPACTED PRODUCTS

- Oracle GlassFish Enterprise Server

DESCRIPTION OF THE VULNERABILITY

A Critical Patch Update corrects several vulnerabilities of GlassFish Enterprise Server.

An attacker can post HTTP data generating storage collisions, in order to overload a remote web server. [severity:2/4; CVE-2011-5035]

An attacker can use a vulnerability of Web Container, in order to create a denial of service. [severity:2/4; BID-51484, CVE-2012-0104]

An attacker can use a vulnerability of Administration, in order to obtain information, to alter information, or to create a denial of service. [severity:2/4; BID-51485, CVE-2012-0081]

An attacker can use a vulnerability of Administration, in order to obtain information. [severity:1/4; BID-51497, CVE-2011-3564]

ACCESS TO THE COMPLETE VIGIL@NCE BULLETIN

http://vigilance.fr/vulnerability/G...


See previous articles

    

See next articles