Description
In Eclipse GlassFish version 7.0.16 or earlier it is possible to perform Login Brute Force attacks as there is no limitation in the number of failed login attempts.
Product(s):
- Eclipse GlassFish 7.0.16
Question to Ask Vendors:
- Can you confirm whether your systems are affected by CVE-2024-9342, and if so, what steps are you currently taking to mitigate this vulnerability?
- What is your estimated timeline for fully resolving CVE-2024-9342 in your products or services, and how will you communicate updates on this issue to us as your customer?
Recommended Actions:
- Check out the advisory links provided below.
References:
- https://capec.mitre.org/data/definitions/16.html
- https://capec.mitre.org/data/definitions/49.html
- https://capec.mitre.org/data/definitions/560.html
- https://capec.mitre.org/data/definitions/565.html
- https://capec.mitre.org/data/definitions/600.html
- https://capec.mitre.org/data/definitions/652.html
- https://capec.mitre.org/data/definitions/653.html
- https://nvd.nist.gov/vuln/detail/CVE-2024-9342