← Vulnerability feed

Vulnerability record · CVE-2009-1553 · published 6 May 2009

CVE-2009-1553: Oracle glassfish server cross-site scripting vulnerability

Oracle · Glassfish Server

Multiple cross-site scripting (XSS) vulnerabilities in the Admin Console in Sun GlassFish Enterprise Server 2.1 allow remote attackers to inject arbitrary web script or HTML via the query string to (1) applications/applications.jsf, (2) configuration/configuration.jsf, (3) customMBeans/customMBeans.jsf, (4) resourceNode/resources.jsf, (5) sysnet/registration.jsf, or (6) webService/webServicesGeneral.jsf; or the name parameter to (7) configuration/auditModuleEdit.jsf, (8) configuration/httpListenerEdit.jsf, or (9) resourceNode/jdbcResourceEdit.jsf.

4.3 CVSS 2.0 Medium EPSS 8.2% · top 5.3% CWE-79 · Cross-site scripting
4.3CVSS 2.0 base score
8.2%EPSS exploitation probability, 30 days
NoNot in CISA KEV
1Affected product versions listed by NVD
46References, 6 tagged exploit
16 Jun 2026Last modified by NVD

Description

Multiple cross-site scripting (XSS) vulnerabilities in the Admin Console in Sun GlassFish Enterprise Server 2.1 allow remote attackers to inject arbitrary web script or HTML via the query string to (1) applications/applications.jsf, (2) configuration/configuration.jsf, (3) customMBeans/customMBeans.jsf, (4) resourceNode/resources.jsf, (5) sysnet/registration.jsf, or (6) webService/webServicesGeneral.jsf; or the name parameter to (7) configuration/auditModuleEdit.jsf, (8) configuration/httpListenerEdit.jsf, or (9) resourceNode/jdbcResourceEdit.jsf.

AV:N/AC:M/Au:N/C:N/I:P/A:N

Affected products

1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

LinkTags
http://dsecrg.com/pages/vul/show.php?id=134 Exploit
http://jvn.jp/en/jp/JVN73653977/index.html
http://jvndb.jvn.jp/en/contents/2009/JVNDB-2009-000027.html
http://osvdb.org/54249
http://osvdb.org/54250
http://osvdb.org/54251
http://osvdb.org/54252
http://osvdb.org/54253
http://osvdb.org/54254
http://osvdb.org/54255
http://osvdb.org/54256
http://osvdb.org/54257
http://sunsolve.sun.com/search/document.do?assetkey=1-26-258528-1
http://www.nabble.com/-DSECRG--Sun-Glassfish-Multiple-Security-Vulnerabilities-p22595435.html Exploit
http://www.nabble.com/Re:--DSECRG--Sun-Glassfish-Multiple-Security-Vulnerabilities-p23002524.html
http://www.securityfocus.com/archive/1/503236/100/0/threaded
http://www.securityfocus.com/bid/34824 Exploit
http://www.securityfocus.com/bid/34914
http://www.vupen.com/english/advisories/2009/1255
https://exchange.xforce.ibmcloud.com/vulnerabilities/50453
https://glassfish.dev.java.net/servlets/ReadMsg?list=cvs&msgNo=29668 PatchVendor Advisory
https://glassfish.dev.java.net/servlets/ReadMsg?list=cvs&msgNo=29669 PatchVendor Advisory
https://glassfish.dev.java.net/servlets/ReadMsg?list=cvs&msgNo=29675 PatchVendor Advisory
http://dsecrg.com/pages/vul/show.php?id=134 Exploit
http://jvn.jp/en/jp/JVN73653977/index.html
http://jvndb.jvn.jp/en/contents/2009/JVNDB-2009-000027.html
http://osvdb.org/54249
http://osvdb.org/54250
http://osvdb.org/54251
http://osvdb.org/54252
http://osvdb.org/54253
http://osvdb.org/54254
http://osvdb.org/54255
http://osvdb.org/54256
http://osvdb.org/54257
http://sunsolve.sun.com/search/document.do?assetkey=1-26-258528-1
http://www.nabble.com/-DSECRG--Sun-Glassfish-Multiple-Security-Vulnerabilities-p22595435.html Exploit
http://www.nabble.com/Re:--DSECRG--Sun-Glassfish-Multiple-Security-Vulnerabilities-p23002524.html
http://www.securityfocus.com/archive/1/503236/100/0/threaded
http://www.securityfocus.com/bid/34824 Exploit

Track CVE-2009-1553 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

10.0CVE-2011-0807Oracle GlassFish and Sun Java System Application Server Administration flawAn unspecified vulnerability in the Administration component of Oracle Sun GlassFish Enterprise Server 2.1, 2.1.1, 3.0.1 and Sun Java System Applicat…EPSS 61%analysed9.8CVE-2018-14324Oracle glassfish server hard-coded credentials vulnerabilityThe demo feature in Oracle GlassFish Open Source Edition 5.0 has TCP port 7676 open by default with a password of admin for the admin account. This a…EPSS 4.3%9.8CVE-2017-1000030Oracle glassfish server improper authentication vulnerabilityOracle, GlassFish Server Open Source Edition 3.0.1 (build 22) is vulnerable to Java Key Store Password Disclosure vulnerability, that makes it possib…EPSS 1.7%9.8CVE-2016-3607Oracle glassfish server vulnerabilityUnspecified vulnerability in the Oracle GlassFish Server component in Oracle Fusion Middleware 3.0.1 and 3.1.2 allows remote attackers to affect conf…EPSS 7.5%9.8CVE-2015-7182Oracle traffic director memory buffer overflow vulnerabilityHeap-based buffer overflow in the ASN.1 decoder in Mozilla Network Security Services (NSS) before 3.19.2.1 and 3.20.x before 3.20.1, as used in Firef…EPSS 10%9.0CVE-2016-5528Oracle glassfish server vulnerabilityVulnerability in the Oracle GlassFish Server component of Oracle Fusion Middleware (subcomponent: Security). Supported versions that are affected are…EPSS 1.8%8.8CVE-2016-5519Oracle glassfish server vulnerabilityUnspecified vulnerability in the Oracle GlassFish Server component in Oracle Fusion Middleware 2.1.1, 3.0.1, and 3.1.2 allows remote authenticated us…EPSS 2.3%8.8CVE-2016-1950Mozilla network security services memory buffer overflow vulnerabilityHeap-based buffer overflow in Mozilla Network Security Services (NSS) before 3.19.2.3 and 3.20.x and 3.21.x before 3.21.1, as used in Mozilla Firefox…EPSS 4.2%

Source: NIST National Vulnerability Database (record CVE-2009-1553), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.