{
    "id": "CVE-2011-0807",
    "published": "2011-04-20 03:14:06",
    "last_modified": "2026-06-16 23:28:06",
    "cvss_score": "10.0",
    "cvss_severity": "HIGH",
    "cvss_version": "2.0",
    "cvss_vector": "AV:N/AC:L/Au:N/C:C/I:C/A:C",
    "cwe": null,
    "description": "Unspecified vulnerability in Oracle Sun GlassFish Enterprise Server 2.1, 2.1.1, and 3.0.1, and Sun Java System Application Server 9.1, allows remote attackers to affect confidentiality, integrity, and availability via unknown vectors related to Administration.",
    "epss_score": "0.60878",
    "epss_percentile": "0.99128",
    "kev": 0,
    "kev_due": null,
    "has_exploit": 1,
    "updated_at": "2026-09-27 18:17:10",
    "priority": {
        "rank": 2,
        "label": "Patch early",
        "why": "A public exploit exists."
    },
    "products": [
        {
            "vendor": "oracle",
            "product": "glassfish_server"
        },
        {
            "vendor": "sun",
            "product": "java_system_application_server"
        }
    ],
    "kev_detail": null,
    "exploits": [
        {
            "source": "exploit-db",
            "ref_id": "17615",
            "title": "Sun/Oracle GlassFish Server - (Authenticated) Code Execution (Metasploit)",
            "date": "2011-08-05",
            "url": "https://www.exploit-db.com/exploits/17615"
        }
    ],
    "refs_list": [
        "http://securityreason.com/securityalert/8327",
        "http://www.oracle.com/technetwork/topics/security/cpuapr2011-301950.html",
        "http://securityreason.com/securityalert/8327",
        "http://www.oracle.com/technetwork/topics/security/cpuapr2011-301950.html"
    ]
}