Vulnerabilities > CVE-2011-3564 - Local Security vulnerability in Oracle SUN Glassfish Enterprise Server 2.1.1

047910
CVSS 2.1 - LOW
Attack vector
LOCAL
Attack complexity
LOW
Privileges required
NONE
Confidentiality impact
PARTIAL
Integrity impact
NONE
Availability impact
NONE
local
low complexity
oracle
nessus

Summary

Unspecified vulnerability in Oracle GlassFish Enterprise Server 2.1.1 allows local users to affect confidentiality via unknown vectors related to Administration.

Vulnerable Configurations

Part Description Count
Application
Oracle
1

Nessus

  • NASL familySolaris Local Security Checks
    NASL idSOLARIS10_X86_128641-30.NASL
    descriptionVulnerability in the Oracle WebLogic Server component of Oracle Fusion Middleware (subcomponent: Web Container). Supported versions that are affected are 9.2.4, 10.0.2, 10.3.5, 10.3.6 and 12.1.1. Easily exploitable vulnerability allows successful unauthenticated network attacks via HTTP. Successful attack of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of Oracle WebLogic Server.
    last seen2020-06-01
    modified2020-06-02
    plugin id107968
    published2018-03-12
    reporterThis script is Copyright (C) 2018-2020 and is owned by Tenable, Inc. or an Affiliate thereof.
    sourcehttps://www.tenable.com/plugins/nessus/107968
    titleSolaris 10 (x86) : 128641-30
    code
    #
    # (C) Tenable Network Security, Inc.
    #
    # The descriptive text in this plugin was
    # extracted from the Oracle SunOS Patch Updates.
    #
    include("compat.inc");
    
    if (description)
    {
      script_id(107968);
      script_version("1.5");
      script_cvs_date("Date: 2020/01/07");
    
      script_cve_id("CVE-2009-0217", "CVE-2009-2625", "CVE-2009-3555", "CVE-2011-3564", "CVE-2011-5035");
    
      script_name(english:"Solaris 10 (x86) : 128641-30");
      script_summary(english:"Check for patch 128641-30");
    
      script_set_attribute(
        attribute:"synopsis", 
        value:"The remote host is missing Sun Security Patch number 128641-30"
      );
      script_set_attribute(
        attribute:"description", 
        value:
    "Vulnerability in the Oracle WebLogic Server component of Oracle Fusion
    Middleware (subcomponent: Web Container). Supported versions that are
    affected are 9.2.4, 10.0.2, 10.3.5, 10.3.6 and 12.1.1. Easily
    exploitable vulnerability allows successful unauthenticated network
    attacks via HTTP. Successful attack of this vulnerability can result
    in unauthorized ability to cause a hang or frequently repeatable crash
    (complete DOS) of Oracle WebLogic Server."
      );
      script_set_attribute(
        attribute:"see_also",
        value:"https://getupdates.oracle.com/readme/128641-30"
      );
      script_set_attribute(attribute:"solution", value:"Install patch 128641-30 or higher");
      script_set_cvss_base_vector("CVSS2#AV:N/AC:M/Au:N/C:N/I:P/A:P");
      script_set_cvss_temporal_vector("CVSS2#E:POC/RL:OF/RC:C");
      script_set_attribute(attribute:"cvss_score_source", value:"CVE-2009-3555");
      script_set_attribute(attribute:"exploitability_ease", value:"Exploits are available");
      script_set_attribute(attribute:"exploit_available", value:"true");
      script_cwe_id(264, 310);
    
      script_set_attribute(attribute:"plugin_type", value:"local");
      script_set_attribute(attribute:"cpe", value:"p-cpe:/a:oracle:solaris:10:128641");
      script_set_attribute(attribute:"cpe", value:"cpe:/o:oracle:solaris:10");
    
      script_set_attribute(attribute:"vuln_publication_date", value:"2009/07/14");
      script_set_attribute(attribute:"patch_publication_date", value:"2012/02/28");
      script_set_attribute(attribute:"plugin_publication_date", value:"2018/03/12");
      script_set_attribute(attribute:"generated_plugin", value:"current");
      script_end_attributes();
    
      script_category(ACT_GATHER_INFO);
      script_copyright(english:"This script is Copyright (C) 2018-2020 and is owned by Tenable, Inc. or an Affiliate thereof.");
      script_family(english:"Solaris Local Security Checks");
    
      script_dependencies("ssh_get_info.nasl");
      script_require_keys("Host/local_checks_enabled", "Host/Solaris/showrev");
    
      exit(0);
    }
    
    
    include("audit.inc");
    include("global_settings.inc");
    include("misc_func.inc");
    include("solaris.inc");
    
    showrev = get_kb_item("Host/Solaris/showrev");
    if (empty_or_null(showrev)) audit(AUDIT_OS_NOT, "Solaris");
    os_ver = pregmatch(pattern:"Release: (\d+.(\d+))", string:showrev);
    if (empty_or_null(os_ver)) audit(AUDIT_UNKNOWN_APP_VER, "Solaris");
    full_ver = os_ver[1];
    os_level = os_ver[2];
    if (full_ver != "5.10") audit(AUDIT_OS_NOT, "Solaris 10", "Solaris " + os_level);
    package_arch = pregmatch(pattern:"Application architecture: (\w+)", string:showrev);
    if (empty_or_null(package_arch)) audit(AUDIT_UNKNOWN_ARCH);
    package_arch = package_arch[1];
    if (package_arch != "i386") audit(AUDIT_ARCH_NOT, "i386", package_arch);
    if (!get_kb_item("Host/local_checks_enabled")) audit(AUDIT_LOCAL_CHECKS_NOT_ENABLED);
    
    if (solaris_check_patch(release:"5.10_x86", arch:"i386", patch:"128641-30", obsoleted_by:"", package:"SUNWasJdbcDrivers", version:"9.1,REV=2007.09.07.14.07") < 0) flag++;
    if (solaris_check_patch(release:"5.10_x86", arch:"i386", patch:"128641-30", obsoleted_by:"", package:"SUNWasac", version:"9.1,REV=2007.09.07.13.59") < 0) flag++;
    if (solaris_check_patch(release:"5.10_x86", arch:"i386", patch:"128641-30", obsoleted_by:"", package:"SUNWasacee", version:"9.1,REV=2007.09.07.14.08") < 0) flag++;
    if (solaris_check_patch(release:"5.10_x86", arch:"i386", patch:"128641-30", obsoleted_by:"", package:"SUNWascml", version:"9.1,REV=2007.09.07.14.08") < 0) flag++;
    if (solaris_check_patch(release:"5.10_x86", arch:"i386", patch:"128641-30", obsoleted_by:"", package:"SUNWascmn", version:"9.1,REV=2007.09.07.14.02") < 0) flag++;
    if (solaris_check_patch(release:"5.10_x86", arch:"i386", patch:"128641-30", obsoleted_by:"", package:"SUNWascmnse", version:"9.1,REV=2007.09.07.14.08") < 0) flag++;
    if (solaris_check_patch(release:"5.10_x86", arch:"i386", patch:"128641-30", obsoleted_by:"", package:"SUNWasdem", version:"9.1,REV=2007.09.07.14.02") < 0) flag++;
    if (solaris_check_patch(release:"5.10_x86", arch:"i386", patch:"128641-30", obsoleted_by:"", package:"SUNWashdm", version:"9.1,REV=2007.09.07.14.07") < 0) flag++;
    if (solaris_check_patch(release:"5.10_x86", arch:"i386", patch:"128641-30", obsoleted_by:"", package:"SUNWasjdoc", version:"9.1,REV=2007.09.07.14.03") < 0) flag++;
    if (solaris_check_patch(release:"5.10_x86", arch:"i386", patch:"128641-30", obsoleted_by:"", package:"SUNWaslb", version:"9.1,REV=2007.09.07.14.04") < 0) flag++;
    if (solaris_check_patch(release:"5.10_x86", arch:"i386", patch:"128641-30", obsoleted_by:"", package:"SUNWasman", version:"9.1,REV=2007.09.07.14.03") < 0) flag++;
    if (solaris_check_patch(release:"5.10_x86", arch:"i386", patch:"128641-30", obsoleted_by:"", package:"SUNWasr", version:"9.1,REV=2007.09.07.14.03") < 0) flag++;
    if (solaris_check_patch(release:"5.10_x86", arch:"i386", patch:"128641-30", obsoleted_by:"", package:"SUNWasu", version:"9.1,REV=2007.09.07.13.59") < 0) flag++;
    if (solaris_check_patch(release:"5.10_x86", arch:"i386", patch:"128641-30", obsoleted_by:"", package:"SUNWasuee", version:"9.1,REV=2007.09.07.14.07") < 0) flag++;
    if (solaris_check_patch(release:"5.10_x86", arch:"i386", patch:"128641-30", obsoleted_by:"", package:"SUNWasut", version:"9.1,REV=2007.09.07.14.03") < 0) flag++;
    if (solaris_check_patch(release:"5.10_x86", arch:"i386", patch:"128641-30", obsoleted_by:"", package:"SUNWaswbcr", version:"9.1,REV=2007.09.07.14.08") < 0) flag++;
    
    if (flag) {
      security_report_v4(
        port       : 0,
        severity   : SECURITY_WARNING,
        extra      : solaris_get_report()
      );
    } else {
      patch_fix = solaris_patch_fix_get();
      if (!empty_or_null(patch_fix)) audit(AUDIT_PATCH_INSTALLED, patch_fix, "Solaris 10");
      tested = solaris_pkg_tests_get();
      if (!empty_or_null(tested)) audit(AUDIT_PACKAGE_NOT_AFFECTED, tested);
      audit(AUDIT_PACKAGE_NOT_INSTALLED, "SUNWasJdbcDrivers / SUNWasac / SUNWasacee / SUNWascml / SUNWascmn / etc");
    }
    
  • NASL familySolaris Local Security Checks
    NASL idSOLARIS9_128640.NASL
    descriptionVulnerability in the Oracle WebLogic Server component of Oracle Fusion Middleware (subcomponent: Web Container). Supported versions that are affected are 9.2.4, 10.0.2, 10.3.5, 10.3.6 and 12.1.1. Easily exploitable vulnerability allows successful unauthenticated network attacks via HTTP. Successful attack of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of Oracle WebLogic Server.
    last seen2020-06-01
    modified2020-06-02
    plugin id35419
    published2009-01-19
    reporterThis script is Copyright (C) 2009-2016 Tenable Network Security, Inc.
    sourcehttps://www.tenable.com/plugins/nessus/35419
    titleSolaris 9 (sparc) : 128640-30
    code
    #
    # (C) Tenable Network Security, Inc.
    #
    # The descriptive text in this plugin was
    # extracted from the Oracle SunOS Patch Updates.
    #
    include("compat.inc");
    
    if (description)
    {
      script_id(35419);
      script_version("$Revision: 1.14 $");
      script_cvs_date("$Date: 2016/12/09 21:14:09 $");
    
      script_cve_id("CVE-2009-0217", "CVE-2009-2625", "CVE-2009-3555", "CVE-2011-3564", "CVE-2011-5035");
    
      script_name(english:"Solaris 9 (sparc) : 128640-30");
      script_summary(english:"Check for patch 128640-30");
    
      script_set_attribute(
        attribute:"synopsis", 
        value:"The remote host is missing Sun Security Patch number 128640-30"
      );
      script_set_attribute(
        attribute:"description", 
        value:
    "Vulnerability in the Oracle WebLogic Server component of Oracle Fusion
    Middleware (subcomponent: Web Container). Supported versions that are
    affected are 9.2.4, 10.0.2, 10.3.5, 10.3.6 and 12.1.1. Easily
    exploitable vulnerability allows successful unauthenticated network
    attacks via HTTP. Successful attack of this vulnerability can result
    in unauthorized ability to cause a hang or frequently repeatable crash
    (complete DOS) of Oracle WebLogic Server."
      );
      script_set_attribute(
        attribute:"see_also",
        value:"https://getupdates.oracle.com/readme/128640-30"
      );
      script_set_attribute(
        attribute:"solution", 
        value:"You should install this patch for your system to be up-to-date."
      );
      script_set_cvss_base_vector("CVSS2#AV:N/AC:M/Au:N/C:N/I:P/A:P");
      script_cwe_id(264, 310);
    
      script_set_attribute(attribute:"plugin_type", value:"local");
      script_set_attribute(attribute:"cpe", value:"cpe:/o:sun:solaris");
    
      script_set_attribute(attribute:"patch_publication_date", value:"2012/03/01");
      script_set_attribute(attribute:"plugin_publication_date", value:"2009/01/19");
      script_end_attributes();
    
      script_category(ACT_GATHER_INFO);
      script_copyright(english:"This script is Copyright (C) 2009-2016 Tenable Network Security, Inc.");
      script_family(english:"Solaris Local Security Checks");
    
      script_dependencies("ssh_get_info.nasl");
      script_require_keys("Host/local_checks_enabled", "Host/Solaris/showrev");
    
      exit(0);
    }
    
    
    include("audit.inc");
    include("global_settings.inc");
    include("solaris.inc");
    
    if (!get_kb_item("Host/local_checks_enabled")) audit(AUDIT_LOCAL_CHECKS_NOT_ENABLED);
    
    if (solaris_check_patch(release:"5.9", arch:"sparc", patch:"128640-30", obsoleted_by:"", package:"SUNWasu", version:"9.1,REV=2007.09.07.14.57") < 0) flag++;
    if (solaris_check_patch(release:"5.9", arch:"sparc", patch:"128640-30", obsoleted_by:"", package:"SUNWashdm", version:"9.1,REV=2007.09.07.15.10") < 0) flag++;
    if (solaris_check_patch(release:"5.9", arch:"sparc", patch:"128640-30", obsoleted_by:"", package:"SUNWasut", version:"9.1,REV=2007.09.07.15.04") < 0) flag++;
    if (solaris_check_patch(release:"5.9", arch:"sparc", patch:"128640-30", obsoleted_by:"", package:"SUNWasman", version:"9.1,REV=2007.09.07.15.04") < 0) flag++;
    if (solaris_check_patch(release:"5.9", arch:"sparc", patch:"128640-30", obsoleted_by:"", package:"SUNWasjdoc", version:"9.1,REV=2007.09.07.15.04") < 0) flag++;
    if (solaris_check_patch(release:"5.9", arch:"sparc", patch:"128640-30", obsoleted_by:"", package:"SUNWaslb", version:"9.1,REV=2007.09.07.15.05") < 0) flag++;
    if (solaris_check_patch(release:"5.9", arch:"sparc", patch:"128640-30", obsoleted_by:"", package:"SUNWascmn", version:"9.1,REV=2007.09.07.15.03") < 0) flag++;
    if (solaris_check_patch(release:"5.9", arch:"sparc", patch:"128640-30", obsoleted_by:"", package:"SUNWasJdbcDrivers", version:"9.1,REV=2007.09.07.15.10") < 0) flag++;
    if (solaris_check_patch(release:"5.9", arch:"sparc", patch:"128640-30", obsoleted_by:"", package:"SUNWasac", version:"9.1,REV=2007.09.07.14.58") < 0) flag++;
    
    if (flag)
    {
      if (report_verbosity > 0) security_warning(port:0, extra:solaris_get_report());
      else security_warning(0);
      exit(0);
    }
    audit(AUDIT_HOST_NOT, "affected");
    
  • NASL familySolaris Local Security Checks
    NASL idSOLARIS9_X86_128641.NASL
    descriptionVulnerability in the Oracle WebLogic Server component of Oracle Fusion Middleware (subcomponent: Web Container). Supported versions that are affected are 9.2.4, 10.0.2, 10.3.5, 10.3.6 and 12.1.1. Easily exploitable vulnerability allows successful unauthenticated network attacks via HTTP. Successful attack of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of Oracle WebLogic Server.
    last seen2020-06-01
    modified2020-06-02
    plugin id35421
    published2009-01-19
    reporterThis script is Copyright (C) 2009-2016 Tenable Network Security, Inc.
    sourcehttps://www.tenable.com/plugins/nessus/35421
    titleSolaris 9 (x86) : 128641-30
  • NASL familySolaris Local Security Checks
    NASL idSOLARIS10_128640-30.NASL
    descriptionVulnerability in the Oracle WebLogic Server component of Oracle Fusion Middleware (subcomponent: Web Container). Supported versions that are affected are 9.2.4, 10.0.2, 10.3.5, 10.3.6 and 12.1.1. Easily exploitable vulnerability allows successful unauthenticated network attacks via HTTP. Successful attack of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of Oracle WebLogic Server.
    last seen2020-06-01
    modified2020-06-02
    plugin id107469
    published2018-03-12
    reporterThis script is Copyright (C) 2018-2020 and is owned by Tenable, Inc. or an Affiliate thereof.
    sourcehttps://www.tenable.com/plugins/nessus/107469
    titleSolaris 10 (sparc) : 128640-30
  • NASL familySolaris Local Security Checks
    NASL idSOLARIS10_128640.NASL
    descriptionVulnerability in the Oracle WebLogic Server component of Oracle Fusion Middleware (subcomponent: Web Container). Supported versions that are affected are 9.2.4, 10.0.2, 10.3.5, 10.3.6 and 12.1.1. Easily exploitable vulnerability allows successful unauthenticated network attacks via HTTP. Successful attack of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of Oracle WebLogic Server. This plugin has been deprecated and either replaced with individual 128640 patch-revision plugins, or deemed non-security related.
    last seen2019-02-21
    modified2018-07-30
    plugin id35409
    published2009-01-19
    reporterTenable
    sourcehttps://www.tenable.com/plugins/index.php?view=single&id=35409
    titleSolaris 10 (sparc) : 128640-30 (deprecated)
  • NASL familyWeb Servers
    NASL idGLASSFISH_CVE-2011-3564.NASL
    descriptionThe version of GlassFish Server running on the remote host is affected by an unspecified vulnerability related to the Administration component that allows local users to affect confidentiality in some way.
    last seen2020-06-01
    modified2020-06-02
    plugin id57803
    published2012-02-02
    reporterThis script is Copyright (C) 2012-2018 and is owned by Tenable, Inc. or an Affiliate thereof.
    sourcehttps://www.tenable.com/plugins/nessus/57803
    titleOracle GlassFish Server 2.1.1 < 2.1.1 Patch15 Administration Component Unspecified Vulnerability
  • NASL familySolaris Local Security Checks
    NASL idSOLARIS10_X86_128641.NASL
    descriptionVulnerability in the Oracle WebLogic Server component of Oracle Fusion Middleware (subcomponent: Web Container). Supported versions that are affected are 9.2.4, 10.0.2, 10.3.5, 10.3.6 and 12.1.1. Easily exploitable vulnerability allows successful unauthenticated network attacks via HTTP. Successful attack of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of Oracle WebLogic Server. This plugin has been deprecated and either replaced with individual 128641 patch-revision plugins, or deemed non-security related.
    last seen2019-02-21
    modified2018-07-30
    plugin id35415
    published2009-01-19
    reporterTenable
    sourcehttps://www.tenable.com/plugins/index.php?view=single&id=35415
    titleSolaris 10 (x86) : 128641-30 (deprecated)