Remote Code Inclusion Vulnerability in Payara Server
CVE-2024-8215
8.4HIGH
What is CVE-2024-8215?
A vulnerability has been identified in the Payara Server, specifically in the Admin Console modules, which results from improper neutralization of input during the generation of web pages. This flaw enables attackers to execute remote code inclusion, potentially compromising the integrity and security of web applications hosted on affected versions of the server. The vulnerability spans several versions, making it critical for organizations using Payara Server to apply the necessary updates and mitigations to protect their systems from exploitation.
Affected Version(s)
Payara Server 5.20.0 < 5.68.0
Payara Server 6.0.0 < 6.19.0
Payara Server 6.2022.1 < 6.2024.10
References
CVSS V3.1
Score:
8.4
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
High
User Interaction:
Required
Scope:
Changed
Timeline
Vulnerability published
Vulnerability Reserved
Credit
Marco Ventura
Claudia Bartolini
Andrea Carlo Maria Dattola
Debora Esposito
Massimiliano Broli