RULE(RULE ID:307055)

Rule General Information
Release Date: 2016-12-28
Rule Name: Oracle Glassfish Enterprise Server REST Interface Cross Site Request Forgery Vulnerability -1 (CVE-2012-0550)
Severity:
CVE ID:
Rule Protection Details
Description: Unspecified vulnerability in the GlassFish Enterprise Server component in Oracle Sun Products Suite GlassFish Enterprise Server 3.1.1 allows remote attackers to affect confidentiality, integrity, and availability via unknown vectors related to Web Container.
Impact: An attacker can launch a cross-site request forgery in the context of the affected software. Arbitrary script transmitted from a user that the software trusts can be executed in a successful exploit attempt.
Affected OS: Others, Solaris, Other Unix, FreeBSD, Linux
Reference: http://www.mandriva.com/security/advisories?name=MDVSA-2013:150
http://www.oracle.com/technetwork/topics/security/cpuapr2012-366314.html
Solutions
More advisories have been published on the website, please visit for more suggestions:
http://www.oracle.com/technetwork/topics/security/cpuapr2012-366314.html