Oracle Sun GlassFish/Java System Application Server Remote Authentication Bypass Vulnerability

Description

Oracle Sun GlassFish/Java System Application Server is prone to a remote authentication-bypass vulnerability. The flaw exists within the Web Administration component which listens by default on TCP port 4848. When handling a malformed GET request to the administrative interface, the application does not properly handle an exception allowing the request to proceed without authentication. A remote attacker can exploit this vulnerability to execute arbitrary code under the context of the application. This vulnerability allows remote attackers to execute arbitrary code on vulnerable installations of Oracle GlassFish Application Server and Oracle Java Application Server. Authentication is not required to exploit this vulnerability. This vulnerability affects the following versions: 2.1, 2.1.1, 3.0.1, 9.1.

Remediation

Vendor updates are available. Please contact the vendor for more information.

References