PT-2022-27409 · Payara · Payara Platform Community+1

·

CVE-2022-45129

·

Published

2022-11-10

·

Updated

2025-05-01

CVSS v3.1

7.5

High

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
Name of the Vulnerable Software and Affected Versions Payara Platform Community versions prior to 4.1.2.191.38 Payara Platform Community versions 5.x prior to 5.2022.4 Payara Platform Community versions 6.x prior to 6.2022.1 Payara Platform Enterprise versions prior to 5.45.0
Description The issue allows attackers to access sensitive directories, specifically META-INF and WEB-INF, when Payara is deployed to the root context. This is a distinct issue from other known vulnerabilities.
Recommendations For Payara Platform Community versions prior to 4.1.2.191.38, update to version 4.1.2.191.38 or later. For Payara Platform Community versions 5.x prior to 5.2022.4, update to version 5.2022.4 or later. For Payara Platform Community versions 6.x prior to 6.2022.1, update to version 6.2022.1 or later. For Payara Platform Enterprise versions prior to 5.45.0, update to version 5.45.0 or later.

Exploit

Fix

Files Accessible to External Parties

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2022-45129
GHSA-Q35W-85PQ-RV3X

Affected Products

Payara Platform Community
Payara Platform Enterprise