CVE-2024-8215 HIGH

CVE-2024-8215: Payload Injection Attack via Management REST interface

Vendor Payara Platform
Product Payara Server
Weakness CWE-79 · XSS
Published October 8, 2024
Last update October 8, 2024

CVSS base score

8.7/10
Attack vector Network
Attack complexity High
Privileges required High
User interaction
Confidentiality
Integrity

CVSS vector

CVSS:4.0/AV:N/AC:H/AT:P/PR:H/UI:A/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H

What the vulnerability does

01Description

Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Payara Platform Payara Server (Admin Console modules) allows Remote Code Inclusion.This issue affects Payara Server: from 5.20.0 before 5.68.0, from 6.0.0 before 6.19.0, from 6.2022.1 before 6.2024.10, from 4.1.2.191.1 before 4.1.2.191.51.

Key dates

02Disclosure timeline

October 8, 2024 CVE published
October 8, 2024 Record updated