PT-2022-23987 · Payara · Payara Server+2

Dudekmar

·

Published

2022-08-18

·

Updated

2025-05-01

·

CVE-2022-37422

CVSS v3.1

7.5

High

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
Name of the Vulnerable Software and Affected Versions Payara versions through 5.2022.2
Description The issue allows directory traversal without authentication, affecting Payara Server, Payara Micro, and Payara Server Embedded.
Recommendations For Payara versions through 5.2022.2, update to a version that contains a fix for this issue to prevent directory traversal without authentication. At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Path traversal

Weakness Enumeration

Related Identifiers

CVE-2022-37422
GHSA-H28C-453M-H9XM

Affected Products

Payara Micro
Payara Server
Payara Server Embedded