This application requires Javascript for optimal performance.

Oracle.GlassFish.Administration.Console.Authentication.Bypass

Release Date

Aug 17, 2011

Severity

medium

Impact

Security Bypass: Remote attackers can bypass security checking of vulnerable systems.

Description

This indicates an attack attempt against an Authentication Bypass vulnerability in Oracle GlassFish.

The vulnerability is due to an error that leads to the software treating HTTP TRACE requests as authenticated GET requests. Attackers can exploit this issue to bypass authentication and perform unauthorized actions.

Affected Products

Oracle Sun GlassFish Enterprise Server Prior to 3.1

Recommended Actions

Refer to the vendor's website for suggested workaround.
http://java.net/jira/browse/GLASSFISH-14078

Coverage

IPS
VCM

Common Vulnerabilities and Exposures (CVE)

CVE-2011-1511

Reference/s

http://www.securityfocus.com/bid/47818 (BugTraq)

Reference: VID-28191