Lucene search

K
cveMitreCVE-2022-45129
HistoryNov 10, 2022 - 6:15 a.m.

CVE-2022-45129

2022-11-1006:15:13
CWE-552
mitre
web.nvd.nist.gov
51
7
payara
cve-2022-45129
security vulnerability
nvd
payara platform community
payara platform enterprise.

CVSS3

7.5

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

HIGH

Integrity Impact

NONE

Availability Impact

NONE

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N

EPSS

0.003

Percentile

71.5%

Payara before 2022-11-04, when deployed to the root context, allows attackers to visit META-INF and WEB-INF, a different vulnerability than CVE-2022-37422. This affects Payara Platform Community before 4.1.2.191.38, 5.x before 5.2022.4, and 6.x before 6.2022.1, and Payara Platform Enterprise before 5.45.0.

Affected configurations

Nvd
Node
payarapayaraRange<4.1.2.191.38community
OR
payarapayaraRange<5.45.0enterprise
OR
payarapayaraRange5.0.05.2022.4community
OR
payarapayaraRange6.0.06.2022.1community
VendorProductVersionCPE
payarapayara*cpe:2.3:a:payara:payara:*:*:*:*:community:*:*:*
payarapayara*cpe:2.3:a:payara:payara:*:*:*:*:enterprise:*:*:*

Social References

More

CVSS3

7.5

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

HIGH

Integrity Impact

NONE

Availability Impact

NONE

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N

EPSS

0.003

Percentile

71.5%