Back to Database
Status published
Medium
CVE-2024-9343
In Eclipse GlassFish version 7.0.15 is possible to perform Stored...
Vulnerability Description
In Eclipse GlassFish version 7.0.15 is possible to perform Stored Cross-site scripting attacks in the Administration Console.
Impact Analysis
Refer to official advisory for detailed impact metrics.
Remediation
Ensure systems are updated to the latest vendor-supplied patch levels.
THREAT MONITOR
Am I Vulnerable?
Launch our assessment wizard to check if your infrastructure is exposed to • CVE-2024-9343
Credits & Attribution
The following person or organization is credited with identifying this vulnerability, as recorded in the NVD database:
- Marco Ventura
- Claudia Bartolini
- Andrea Carlo Maria Dattola
- Debora Esposito
- Massimiliano Brolli
More from Eclipse Foundation
View All →CVE-2025-7962
In Jakarta Mail versions prior to 2.0.2 it is possible...
Medium
6
CVE-2025-6705
A vulnerability in the Eclipse Open VSX Registry’s automated publishing...
High
7.6
CVE-2025-55102
A denial-of-service vulnerability exists in the NetX IPv6 component functionality...
High
8.7
CVE-2025-55100
Potential out-of-bounds read in _ux_host_class_audio10_sam_parse_func()
Low
2.4
CVE-2025-55099
Potential out-of-bounds read in _ux_host_class_audio_alternate_setting_locate()
Low
2.4
Affected Vendor
Eclipse Foundation
View all reports →Affected Software
Eclipse Glassfish
Vulnerable Versions:
7.0.15
Timeline
Official Publish:
July 16th, 2025
Last Modified:
July 16th, 2025
Added to House:
July 22nd, 2026