Vulnerability index

Browse CVEs

8 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Payara MEDIUM 5.4
CVE-2025-1534

CVE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Payara Platform Payara Server allows : …

Fix: 4.1.2.191.51 / 5.68.0+
Fix from $1,600 2025-04-01
Payara HIGH 8.4
CVE-2024-8215

Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Payara Platform Payara Server (Admin Con…

Fix: 4.1.2.191.51 / 5.68.0+
Fix from $1,950 2024-10-08
Payara MEDIUM 6.1
CVE-2024-7312

URL Redirection to Untrusted Site ('Open Redirect') vulnerability in Payara Platform Payara Server (REST Management Interface modules) allows Session…

Fix: 4.1.2.191.50 / 5.67.0+
Fix from $1,600 2024-09-11
Payara MEDIUM 6.1
CVE-2023-41699

URL Redirection to Untrusted Site ('Open Redirect') vulnerability in Payara Platform Payara Server, Micro and Embedded (Servlet Implementation module…

Fix: 4.1.2.191.46 / 5.57.0+
Fix from $1,600 2023-11-15
Payara Server CRITICAL 9.8
CVE-2023-28462

A JNDI rebind operation in the default ORB listener in Payara Server 4.1.2.191 (Enterprise), 5.20.0 and newer (Enterprise), and 5.2020.1 and newer (C…

Fix: after 5.0.0
Fix from $2,300 2023-03-30
Payara HIGH 7.5
CVE-2022-45129

Payara before 2022-11-04, when deployed to the root context, allows attackers to visit META-INF and WEB-INF, a different vulnerability than CVE-2022-…

Fix: 4.1.2.191.38 / 5.45.0+
Fix from $1,950 2022-11-10
Payara HIGH 7.5
CVE-2022-37422

Payara through 5.2022.2 allows directory traversal without authentication. This affects Payara Server, Payara Micro, and Payara Server Embedded.

Fix: 4.1.2.191.36 / 5.42.0+
Fix from $1,950 2022-08-18
Micro Community HIGH 7.5
CVE-2021-41381EPSS 53%

Payara Micro Community 5.2021.6 and below allows Directory Traversal.

Fix: after 5.2021.6
Fix from $1,950 2021-09-23