Loading
Oracle, GlassFish Server Open Source Edition 4.1 is vulnerable to both authenticated and unauthenticated Directory Traversal vulnerability, that can be exploited by issuing a specially crafted HTTP GET request.
Use CWE-22, Oracle vendor hub and Glassfish Server product page to widen CVE-2017-1000028 into its surrounding weakness, vendor, and product context.
Compare it with CVE-2018-14324, CVE-2017-1000030 and CVE-2018-2911 for nearby disclosures in the same product family.