CVE-2024-7312: Payara

Medium severity, CVSS 6.1. EPSS: 0.2% chance of exploitation in the next 30 days.

URL Redirection to Untrusted Site ('Open Redirect') vulnerability in Payara Platform Payara Server (REST Management Interface modules) allows Session Hijacking.This issue affects Payara Server: from 6.0.0 before 6.18.0, from 6.2022.1 before 6.2024.9, from 5.2020.2 before 5.2022.5, from 5.20.0 before 5.67.0, from 4.1.2.191.0 before 4.1.2.191.50.

Affected products

  • Payara Payara: from 4.1.2.191.0, before 4.1.2.191.50 (fixed in 4.1.2.191.50); from 5.20.0, before 5.67.0 (fixed in 5.67.0); from 5.2020.2, before 5.2022.5 (fixed in 5.2022.5); from 6.0.0, before 6.18.0 (fixed in 6.18.0); from 6.2022.1, before 6.2024.9 (fixed in 6.2024.9)

Published 2024-09-11. Last modified 2026-06-17.