CVE-2017-1000028: Oracle Glassfish Server

High severity, CVSS 7.5. EPSS: 99.5% chance of exploitation in the next 30 days.

Oracle, GlassFish Server Open Source Edition 4.1 is vulnerable to both authenticated and unauthenticated Directory Traversal vulnerability, that can be exploited by issuing a specially crafted HTTP GET request.

Affected products

  • Oracle Glassfish Server: version 4.1 only

Published 2017-07-17. Last modified 2026-06-17.