Vulnerabilities > Oracle > Glassfish Server > 3.1

DATE CVE VULNERABILITY TITLE RISK
2021-06-25 CVE-2021-3314 Cross-site Scripting vulnerability in Oracle Glassfish Server
Oracle GlassFish Server 3.1.2.18 and below allows /common/logViewer/logViewer.jsf XSS.
network
low complexity
oracle CWE-79
6.1
2011-12-30 CVE-2011-5035 Improper Input Validation vulnerability in Oracle Glassfish Server
Oracle Glassfish 2.1.1, 3.0.1, and 3.1.1, as used in Communications Server 2.0, Sun Java System Application Server 8.1 and 8.2, and possibly other products, computes hash values for form parameters without restricting the ability to trigger hash collisions predictably, which allows remote attackers to cause a denial of service (CPU consumption) by sending many crafted parameters, aka Oracle security ticket S0104869.
network
low complexity
oracle CWE-20
5.0