Vulnerabilities > Eclipse > Glassfish

DATE CVE VULNERABILITY TITLE RISK
2023-11-03 CVE-2023-5763 Improper Control of Dynamically-Managed Code Resources vulnerability in Eclipse Glassfish 5.1.0/6.0.0/6.2.5
In Eclipse Glassfish 5 or 6, running with old versions of JDK (lower than 6u211, or < 7u201, or < 8u191), allows remote attackers to load malicious code on the server via access to insecure ORB listeners.
network
low complexity
eclipse CWE-913
critical
9.8
2023-01-27 CVE-2022-2712 Path Traversal vulnerability in Eclipse Glassfish 5.1.0/6.0.0/6.2.5
In Eclipse GlassFish versions 5.1.0 to 6.2.5, there is a vulnerability in relative path traversal because it does not filter request path starting with './'.
network
low complexity
eclipse CWE-22
7.5