Common vulnerabilities and Exposures (CVE)

Skip to main content

Required CVE Record Information

Description

CVE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Payara Platform Payara Server allows : Remote Code Inclusion.This issue affects Payara Server: from 4.1.2.1919.1 before 4.1.2.191.51, from 5.20.0 before 5.68.0, from 6.0.0 before 6.23.0, from 6.2022.1 before 6.2025.2.

CVSS 1 Total

ScoreSeverityVersionVector String
6.8MEDIUM4.0CVSS:4.0/AV:N/AC:L/AT:P/PR:H/UI:A/VC:N/VI:H/VA:N/SC:N/SI:H/SA:N/R:U

Product Status

Learn more

Versions 4 Total

Default Status: unaffected

affected

Credits

  • Marco Ventura reporter
  • Claudia Bartolini reporter
  • Massimiliano Brolli reporter

Authorized Data Publishers