PT-2025-14021 · Payara · Payara Server

Claudia Bartolini

+2

·

Published

2025-04-01

·

Updated

2025-10-14

·

CVE-2025-1534

CVSS v4.0

6.8

Medium

VectorAV:N/AC:L/AT:P/PR:H/UI:A/VC:N/VI:H/VA:N/SC:N/SI:H/SA:N/R:U
Name of the Vulnerable Software and Affected Versions Payara Server versions 4.1.2.1919.1 through 4.1.2.191.51 Payara Server versions 5.20.0 through 5.68.0 Payara Server versions 6.0.0 through 6.23.0 Payara Server versions 6.2022.1 through 6.2025.2
Description The issue affects Payara Server, allowing remote code inclusion due to improper neutralization of input during web page generation, also known as cross-site scripting.
Recommendations For Payara Server versions 4.1.2.1919.1 through 4.1.2.191.51, update to version 4.1.2.191.51 or later. For Payara Server versions 5.20.0 through 5.68.0, update to version 5.68.0 or later. For Payara Server versions 6.0.0 through 6.23.0, update to version 6.23.0 or later. For Payara Server versions 6.2022.1 through 6.2025.2, update to version 6.2025.2 or later.

Fix

XSS

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2025-1534

Affected Products

Payara Server