Eclipse GlassFish
cpe:2.3:a:eclipse:glassfish:*:*:*:*:*:*:*
- 7.1.0
- 8.0.0
A remote code execution vulnerability has been identified in the Eclipse GlassFish Administration Console, specifically in versions 7.1.0 and 8.0.0. This vulnerability allows authenticated users with access to the console to send crafted requests that execute arbitrary operating system commands. The commands are executed with the privileges of the application service user.
Exploitation of this vulnerability allows for authenticated remote code execution on the server, with the executed commands running under the application's service user privileges.
Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.