{"id":"CVE-2023-5763","summary":"Glassfish remote code execution","details":"In Eclipse Glassfish 5 or 6, running with old versions of JDK (lower than 6u211, or \u003c 7u201, or \u003c 8u191), allows remote attackers to load malicious code on the server via access to insecure ORB listeners.\n","aliases":["GHSA-2mw4-wj8c-7f93"],"modified":"2026-08-12T03:51:38.032463491Z","published":"2023-11-03T06:40:43.441Z","database_specific":{"cna_assigner":"eclipse","cwe_ids":["CWE-20","CWE-913"],"osv_generated_from":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2023/5xxx/CVE-2023-5763.json","unresolved_ranges":[{"source":"AFFECTED_FIELD","extracted_events":[{"introduced":"6.0.0"},{"last_affected":"6.2.5"},{"introduced":"5.0"},{"last_affected":"5.1"}]}]},"references":[{"type":"WEB","url":"https://glassfish.org/docs/latest/security-guide.html#securing-glassfish-server"},{"type":"ADVISORY","url":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2023/5xxx/CVE-2023-5763.json"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2023-5763"},{"type":"REPORT","url":"https://gitlab.eclipse.org/security/cve-assignement/-/issues/14"}],"affected":[{"ranges":[{"type":"GIT","repo":"https://github.com/eclipse-ee4j/glassfish","events":[{"introduced":"0"},{"last_affected":"0159b68b362c7f4be78d1fa75aeaf2ec0b997f1d"}],"database_specific":{"source":"CPE_RANGE","cpe":"cpe:2.3:a:eclipse:glassfish:*:*:*:*:*:*:*:*","extracted_events":[{"introduced":"5.0.0"},{"last_affected":"6.2.5"}]}}],"versions":["initial-contribution","6.2.5","6.1.0-M1","M2-servlet5","6.0.0-M2-servlet5"],"database_specific":{"source":"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2023-5763.json"}}],"schema_version":"1.9.0","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:N"}]}