← Vulnerability feed

Vulnerability record · CVE-2011-0807 · published 20 April 2011

CVE-2011-0807: Oracle GlassFish and Sun Java System Application Server Administration flaw

Oracle · Glassfish Server

An unspecified vulnerability in the Administration component of Oracle Sun GlassFish Enterprise Server 2.1, 2.1.1, 3.0.1 and Sun Java System Application Server 9.1 allows remote attackers to affect confidentiality, integrity and availability. The record gives no root cause, affected endpoint or code path, so the exact flaw cannot be described beyond the Administration component.

10.0 CVSS 2.0 High EPSS 61% · top 0.9%
10.0CVSS 2.0 base score
61%EPSS exploitation probability, 30 days
NoNot in CISA KEV
2Affected product versions listed by NVD
4References
16 Jun 2026Last modified by NVD

Description

Unspecified vulnerability in Oracle Sun GlassFish Enterprise Server 2.1, 2.1.1, and 3.0.1, and Sun Java System Application Server 9.1, allows remote attackers to affect confidentiality, integrity, and availability via unknown vectors related to Administration.

AV:N/AC:L/Au:N/C:C/I:C/A:C

Automated analysis

Generated by VULONE's analysis model from the NVD record, CISA KEV and EPSS data on 19 September 2026. Confidence: medium.

critical priorityCVSS 2.0 is 10.0 with network, no-auth, no-interaction access and full C/I/A impact, and EPSS is above the 99th percentile, so the flaw is both severe and likely to be targeted.

What it is

An unspecified vulnerability in the Administration component of Oracle Sun GlassFish Enterprise Server 2.1, 2.1.1, 3.0.1 and Sun Java System Application Server 9.1 allows remote attackers to affect confidentiality, integrity and availability. The record gives no root cause, affected endpoint or code path, so the exact flaw cannot be described beyond the Administration component.

Impact

A remote attacker can fully compromise confidentiality, integrity and availability of the affected server, consistent with the CVSS 2.0 score of 10.0. This means potential read and modification of application data and disruption of the server.

Attack surface

The vector is AV:N/AC:L/Au:N, so the flaw is reachable over the network with no authentication and no user interaction. The description points to the Administration interface as the entry point, but the specific request or endpoint is not stated.

Exploitation

The record is not listed in CISA KEV and no ransomware usage is documented; EPSS is 0.60878 (99.1st percentile), indicating a high predicted likelihood of exploitation activity. Reference tags only mark a vendor patch/advisory, with no public exploit or PoC tag.

What to do

  • Apply the Oracle April 2011 Critical Patch Update referenced in the vendor advisory for the affected GlassFish and Java System Application Server versions.
  • If the Administration interface is not required, disable it or restrict network access to it with firewall rules and bind it to trusted management networks only.
  • Place the administration port behind an authenticated reverse proxy or VPN so unauthenticated remote access is not possible.
  • Monitor vendor advisories for any follow-up guidance, since the record does not specify the vulnerable code path.

Detection

  • Review web and application server logs for unexpected or anomalous requests to the GlassFish/Sun Java System Application Server administration endpoints.
  • Alert on administration interface access from untrusted source IPs or outside normal management windows.
  • Baseline normal administration traffic and flag new user agents, request patterns or error spikes against the admin port.
  • Correlate server-side process or file integrity changes with admin interface activity to catch post-exploitation tampering.

This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.

Affected products

2 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2011-0807 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

9.8CVE-2018-14324Oracle glassfish server hard-coded credentials vulnerabilityThe demo feature in Oracle GlassFish Open Source Edition 5.0 has TCP port 7676 open by default with a password of admin for the admin account. This a…EPSS 4.3%9.8CVE-2017-1000030Oracle glassfish server improper authentication vulnerabilityOracle, GlassFish Server Open Source Edition 3.0.1 (build 22) is vulnerable to Java Key Store Password Disclosure vulnerability, that makes it possib…EPSS 1.7%9.8CVE-2016-3607Oracle glassfish server vulnerabilityUnspecified vulnerability in the Oracle GlassFish Server component in Oracle Fusion Middleware 3.0.1 and 3.1.2 allows remote attackers to affect conf…EPSS 7.5%9.8CVE-2015-7182Oracle traffic director memory buffer overflow vulnerabilityHeap-based buffer overflow in the ASN.1 decoder in Mozilla Network Security Services (NSS) before 3.19.2.1 and 3.20.x before 3.20.1, as used in Firef…EPSS 10%9.3CVE-2007-3715Sun java system application server improper input validation vulnerabilitySun Java System Application Server and Web Server 7.0 through 9.0 before 20070710 do not properly process XSLT stylesheets in XSLT transforms in XML …EPSS 2.3%9.0CVE-2016-5528Oracle glassfish server vulnerabilityVulnerability in the Oracle GlassFish Server component of Oracle Fusion Middleware (subcomponent: Security). Supported versions that are affected are…EPSS 1.8%8.8CVE-2016-5519Oracle glassfish server vulnerabilityUnspecified vulnerability in the Oracle GlassFish Server component in Oracle Fusion Middleware 2.1.1, 3.0.1, and 3.1.2 allows remote authenticated us…EPSS 2.3%8.8CVE-2016-1950Mozilla network security services memory buffer overflow vulnerabilityHeap-based buffer overflow in Mozilla Network Security Services (NSS) before 3.19.2.3 and 3.20.x and 3.21.x before 3.21.1, as used in Mozilla Firefox…EPSS 4.2%

Source: NIST National Vulnerability Database (record CVE-2011-0807), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.