HtmlUnit is a GUI-less browser for Java programs. HtmlUnit is vulnerable to Remote Code Execution (RCE) via XSTL, when browsing the attacker’s webpage. This vulnerability has been patched in version 3.9.0
CVSS Details
- CVSS 3.1 Base Score: 9.8
- CVSS 3.1 Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H)
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Oracle Weblogic | — | Apply the Patch Set Update (PSU) 36155700 for version 12.2.1.4.0.Apply the Patch Set Update (PSU) 36124787 for version 14.1.1.0.0. | Feb 2, 2024 | Dec 4, 2023 |
| Ubuntu | — | Upgrade libhtmlunit-java (Ubuntu Pro) | May 25, 2026 | May 5, 2026 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub