VendorsEclipseglassfishall versions
Vulnerabilities

Eclipse GlassFish

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

13CVEs
CVE-2023-5763
Glassfish remote code execution
Published 2023-11-03 · Modified
9.8EPSS 0.007
CVE-2024-9342
In Eclipse GlassFish versions before 8.0.3 it is possible to perform Login Brute Force attacks as there is no limitation in the number of failed login attempts. GlassFish 8.0.3 adds automatic attack protection documented in https://glassfish.org/docs/latest/security-guide.html#brute-force-attack-protection .
Published 2025-07-16 · Modified
9.8EPSS 0.004
CVE-2024-9408
In Eclipse GlassFish since version 6.2.5 it is possible to perform a Server Side Request Forgery attack in specific endpoints.
Published 2025-07-16 · Analyzed
9.8EPSS 0.003
CVE-2026-2587
A critical Remote Code Execution (RCE) vulnerability was identified in the server-side template rendering mechanism used by the Glassfish gadget handler. The application processes .xml files and evaluates user-supplied values within a context where Expression Language (EL) “expressions” are processed without proper sanitization or escaping. By injecting expressions such as #{7*7}, the server returns 49, confirming server-side EL evaluation. This issue allows a remote attacker to fully compromise the underlying host, enabling capabilities as reading/modifying data, executing arbitrary commands, persistence, and lateral movement. This issue affects Eclipse GlassFish: from 8.0.0 to 8.0.1, fixed in 8.0.2; 7.1.0, fixed in 7.1.1; from 7.0.0 to 7.0.25, fixed in 7.0.26. Impact on versions from 5.1.0 to 6.2.5 is unknown.
Published 2026-05-19 · Modified
9.6EPSS 0.006
CVE-2026-12605
In Eclipse GlassFish versions 8.0.x before 8.0.4, CSRF + SSRF in DownloadServlet ContentSources leaks the admin `gfresttoken` to attacker-controlled host if the victim is authenticated into the Admin Console -\> full unauthenticated takeover of Eclipse GlassFish domain until the token expires.
Published 2026-08-06 · Analyzed
9.6EPSS 0.003
CVE-2026-2586
An authenticated Remote Code Execution (RCE) vulnerability was identified in GlassFish's Administration Console. A user with access to the panel can send crafted requests that allow the execution of arbitrary operating system commands with the privileges of the application service user. This issue affects Eclipse GlassFish: from 8.0.0 to 8.0.1, fixed in 8.0.2; 7.1.0, fixed in 7.1.1; from 7.0.0 to 7.0.25, fixed in 7.0.26. Impact on versions from 5.1.0 to 6.2.5 is unknown.
Published 2026-05-19 · Modified
9.1EPSS 0.008
CVE-2022-2712
In Eclipse GlassFish versions 5.1.0 to 6.2.5, there is a vulnerability in relative path traversal because it does not filter request path starting with './'. Successful exploitation could allow an remote unauthenticated attacker to access critical data, such as configuration files and deployed application source code. This is fixed in GlassFish 7.0.0.
Published 2023-01-27 · Modified
7.5EPSS 0.009
CVE-2024-9329
Glassfish redirect to untrusted site
Published 2024-09-30 · Modified
6.9EPSS 0.007
CVE-2024-8646
Eclipse Glassfish: URL redirection vulnerability to untrusted sites
Published 2024-09-11 · Analyzed
6.1EPSS 0.004
CVE-2024-9343
In Eclipse GlassFish version 7.0.15 is possible to perform Stored Cross-site scripting attacks in the Administration Console.
Published 2025-07-16 · Analyzed
6.1EPSS 0.002
CVE-2024-10032
In Eclipse GlassFish version 7.0.15 is possible to perform Stored Cross-site scripting attacks in the Administration Console.
Published 2025-07-16 · Analyzed
6.1EPSS 0.002
CVE-2024-10029
In Eclipse GlassFish version 7.0.15 is possible to perform Reflected Cross-site scripting attacks in the Administration Console.
Published 2025-07-16 · Analyzed
6.1EPSS 0.002
CVE-2024-10031
In Eclipse GlassFish version 7.0.15 is possible to perform Stored Cross-site Scripting attacks by modifying the configuration file in the underlying operating system.
Published 2025-07-16 · Analyzed
5.8EPSS 0.002