Oracle GlassFish Server Open Source Edition 4.1 is vulnerable to both authenticated and unauthenticated local file inclusion vulnerabilities that can be exploited by issuing specially crafted HTTP GET requests.
id: CVE-2017-1000028
info:
name: Oracle GlassFish Server Open Source Edition 4.1 - Local File Inc
...