~ubuntu-security/ubuntu-cve-tracker/master

« back to all changes in this revision

Viewing changes to retired/CVE-2017-3239

  • Committer: Steve Beattie
  • Date: 2019-02-19 06:18:27 UTC
  • Revision ID: sbeattie@ubuntu.com-20190219061827-oh57fzcfc1u9dlfk
The ubuntu-cve-tracker project has been converted to git.

Please use 'git clone https://git.launchpad.net/ubuntu-cve-tracker' to
get the converted tree.

Show diffs side-by-side

added added

removed removed

Lines of Context:
1
 
Candidate: CVE-2017-3239
2
 
PublicDate: 2017-01-27
3
 
References:
4
 
 https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2017-3239
5
 
 http://www.oracle.com/ocom/groups/public/@otn/documents/webcontent/3432537.xml
6
 
 http://www.oracle.com/technetwork/security-advisory/cpujan2017-2881727.html#AppendixFMW
7
 
Description:
8
 
 Vulnerability in the Oracle GlassFish Server component of Oracle Fusion
9
 
 Middleware (subcomponent: Administration). Supported versions that are
10
 
 affected are 3.0.1 and 3.1.2. Easily exploitable vulnerability allows low
11
 
 privileged attacker with logon to the infrastructure where Oracle GlassFish
12
 
 Server executes to compromise Oracle GlassFish Server. Successful attacks
13
 
 of this vulnerability can result in unauthorized read access to a subset of
14
 
 Oracle GlassFish Server accessible data. CVSS v3.0 Base Score 3.3
15
 
 (Confidentiality impacts).
16
 
Ubuntu-Description:
17
 
Notes:
18
 
 sbeattie> glassfish 3.x only
19
 
Bugs:
20
 
Priority: medium
21
 
Discovered-by:
22
 
Assigned-to:
23
 
 
24
 
Patches_glassfish:
25
 
upstream_glassfish: needs-triage
26
 
precise_glassfish: not-affected (3.x only)
27
 
trusty_glassfish: not-affected (3.x only)
28
 
vivid/stable-phone-overlay_glassfish: DNE
29
 
vivid/ubuntu-core_glassfish: DNE
30
 
xenial_glassfish: not-affected (3.x only)
31
 
yakkety_glassfish: not-affected (3.x only)
32
 
devel_glassfish: not-affected (3.x only)