In Eclipse Glassfish 5 or 6, running with old versions of JDK (lower than 6u211, or < 7u201, or < 8u191), allows remote attackers to load malicious code on the server via access to insecure ORB listeners.
| Software | From | Fixed in |
|---|---|---|
org.glassfish.main.orb / orb-connector
|
5.0.0 | 7.0.0 |
| eclipse / glassfish | 5.0.0 | 6.2.5.x |