In Oracle GlassFish Open Source Edition 5.0, the demo feature exposes TCP port 7676 by default and uses 'admin' as the default password for the admin account. This configuration allows remote attackers to connect via JMX RMI and potentially obtain sensitive information, perform database operations, or manipulate the demo environment. The vulnerability arises from the use of hardcoded credentials and an exposed management interface.
Mallory correlates every CVE against your assets, your vendors, and active adversary campaigns. Know which vulnerabilities matter for you, not just which ones are loud.
What it means. What to do now. Patch path, mitigations, and the assume-compromise checklist.
What an attacker gets, and what they’ve been doing with it.
If you can’t patch tonight, do this now.
Patch, then assume compromise.
1 valid exploit after Mallory filtered fakes, detection scripts, and README-only repos.
This repository provides two Java proof-of-concept tools (DumpJMX.java and DiagnosticCommand.java) for exploiting CVE-2018-14324 in Eclipse GlassFish 5. The tools connect to a remote JMX RMI endpoint (typically on ports 7676 and 8686), authenticate (default admin/admin), and enumerate all available MBeans, their attributes, and operations. DiagnosticCommand.java specifically invokes the 'vmSystemProperties' operation to dump JVM system properties, which may contain sensitive information. The README.md provides detailed instructions for identifying vulnerable targets, enumerating MBeans, and leveraging the MLet MBean for remote code execution (RCE) using external tools like Beanshooter. The code itself does not directly achieve RCE but is instrumental in reconnaissance and information gathering, which are prerequisites for successful exploitation. The repository is structured with two main Java files (DumpJMX.java for broad enumeration and DiagnosticCommand.java for targeted property dumping) and a comprehensive README.md explaining the vulnerability, exploitation steps, and references.
Products and vendors Mallory has correlated with this vulnerability. Open in Mallory to drill down to specific CPE configurations and version ranges.
Vendor-confirmed product mapping. Mallory continuously reconciles this list against your asset inventory.
No public activity tracked yet. Mallory keeps watching.
No public activity observed for this vulnerability.
Query your assets running an affected version, and investigate the blast radius.
Every observed campaign linking this CVE to a named adversary.
Malware families riding this exploit, with evidence and IOCs.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Cross-references every affected SKU, including bundled OEM variants.
Community discussion across Reddit, Mastodon, and other social sources.