Vulnerability GHSA-q35w-85pq-rv3x

High Risk
HIGH RISK
CVSS Score: 7.5
Score Range: 7.0–8.9
High severity vulnerabilities (CVSS 7.0–8.9). Serious vulnerabilities that should be prioritized soon after critical fixes.
3 years ago
November 10, 2022 at 12:01 PM UTC
Payara, when deployed to the root context, allows attackers to visit META-INF and WEB-INF
5.181.0 - 5.184.0 and 5.191.0 - 5.194.0 and 5.201.0 and 6.2022.1
5.181.0 - 5.184.0 and 5.191.0 - 5.194.0 and 5.201.0 and 6.2022.1

Summary

Payara, when deployed to the root context, allows attackers to visit META-INF and WEB-INF

Details

Payara before 2022-11-04, when deployed to the root context, allows attackers to visit META-INF and WEB-INF, a different vulnerability than CVE-2022-37422. This affects Payara Platform Community before 4.1.2.191.38, 5.x before 5.2022.4, and 6.x before 6.2022.1, and Payara Platform Enterprise before 5.45.0.

Timeline

Published
3 years ago
November 10, 2022 at 12:01 PM UTC
Fixed (6.2022.2)
Unknown
Unknown
Fixed (5.2022.5)
Unknown
Unknown
Last Modified
1 year ago
September 04, 2025 at 06:57 PM UTC