CVEFinder.io

CVE-2024-9342

⛔ critical
🔍 Scan for this CVE
Summary

In Eclipse GlassFish version 7.0.16 or earlier it is possible to perform Login Brute Force attacks as there is no limitation in the number of failed login attempts.

CVSS Score
9.8
Critical
EPSS Score
0.1
Exploit Probability
Published Date
2025-07-16
First Seen: 2026-01-05
📊 Relative Risk Intelligence

This CVE is Very High Risk - more severe than 90.5% of all 326,604 vulnerabilities in our database.

#31,067
Top 10% most severe
Severity Percentile
Last Modified 2025-07-16
Source NVD 🔗
CVSS Vector 3.1 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
CVSS Vector 4.0 CVSS:4.0/AV:A/AC:L/AT:N/PR:N/UI:N/VC:L/VI:N/VA:N/SC:H/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
CWE IDs (Weakness Types)

📦 Affected Products 1

🔗 References 1

🔗 Related CVEs 6

CVE ID Severity CVSS EPSS Summary Published
CVE-2026-2586 ⛔ critical 9.1 0.3 An authenticated Remote Code Execution (RCE) vulnerability was identified in GlassFish's Administration Console. A user ... 2026-05-19
CVE-2026-2587 ⛔ critical 9.6 0.2 A critical Remote Code Execution (RCE) vulnerability was identified in the server-side template rendering mechanism used... 2026-05-19
CVE-2024-10029 🔶 medium 6.1 0.0 In Eclipse GlassFish version 7.0.15 is possible to perform Reflected Cross-site scripting attacks in the Administration ... 2025-07-16
CVE-2024-10031 🔶 medium 5.4 0.0 In Eclipse GlassFish version 7.0.15 is possible to perform Stored Cross-site Scripting attacks by modifying the configur... 2025-07-16
CVE-2024-10032 🔶 medium 5.4 0.0 In Eclipse GlassFish version 7.0.15 is possible to perform Stored Cross-site scripting attacks in the Administration Con... 2025-07-16
CVE-2024-9343 🔶 medium 6.1 0.0 In Eclipse GlassFish version 7.0.15 is possible to perform Stored Cross-site scripting attacks in the Administration Con... 2025-07-16
These CVEs affect the same products