In Eclipse GlassFish since version 6.2.5 it is possible to perform a Server Side Request Forgery attack in specific endpoints.
Metrics
Affected Vendors & Products
References
History
Wed, 16 Jul 2025 20:00:00 +0000
Type | Values Removed | Values Added |
---|---|---|
First Time appeared |
Eclipse
Eclipse glassfish |
|
CPEs | cpe:2.3:a:eclipse:glassfish:6.2.5:*:*:*:*:*:*:* | |
Vendors & Products |
Eclipse
Eclipse glassfish |
|
Metrics |
cvssV3_1
|
Wed, 16 Jul 2025 16:15:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Metrics |
ssvc
|
Wed, 16 Jul 2025 13:45:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Metrics |
epss
|
Wed, 16 Jul 2025 11:30:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Description | In Eclipse GlassFish since version 6.2.5 it is possible to perform a Server Side Request Forgery attack in specific endpoints. | |
Weaknesses | CWE-918 | |
References |
| |
Metrics |
cvssV4_0
|

Status: PUBLISHED
Assigner: eclipse
Published: 2025-07-16T11:15:03.412Z
Updated: 2025-07-16T15:53:13.391Z
Reserved: 2024-10-01T11:12:54.360Z
Link: CVE-2024-9408

Updated: 2025-07-16T15:53:06.026Z

Status : Analyzed
Published: 2025-07-16T12:15:23.227
Modified: 2025-07-16T19:54:17.417
Link: CVE-2024-9408

No data.