Back to Database
Status published
High
CVE-2024-9408
In Eclipse GlassFish since version 6.2.5 it is possible to...
Vulnerability Description
In Eclipse GlassFish since version 6.2.5 it is possible to perform a Server Side Request Forgery attack in specific endpoints.
Impact Analysis
Refer to official advisory for detailed impact metrics.
Remediation
Ensure systems are updated to the latest vendor-supplied patch levels.
THREAT MONITOR
Am I Vulnerable?
Launch our assessment wizard to check if your infrastructure is exposed to • CVE-2024-9408
Credits & Attribution
The following person or organization is credited with identifying this vulnerability, as recorded in the NVD database:
- Mustafa GÜNDOĞDU
More from Eclipse Foundation
View All →CVE-2025-7962
In Jakarta Mail versions prior to 2.0.2 it is possible...
Medium
6
CVE-2025-6705
A vulnerability in the Eclipse Open VSX Registry’s automated publishing...
High
7.6
CVE-2025-55102
A denial-of-service vulnerability exists in the NetX IPv6 component functionality...
High
8.7
CVE-2025-55100
Potential out-of-bounds read in _ux_host_class_audio10_sam_parse_func()
Low
2.4
CVE-2025-55099
Potential out-of-bounds read in _ux_host_class_audio_alternate_setting_locate()
Low
2.4
Affected Vendor
Eclipse Foundation
View all reports →Affected Software
Eclipse Glassfish
Vulnerable Versions:
6.2.5
Timeline
Official Publish:
July 16th, 2025
Last Modified:
July 16th, 2025
Added to House:
July 22nd, 2026