CVE-2024-8215: Payara
High severity, CVSS 8.4. EPSS: 0.5% chance of exploitation in the next 30 days.
Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Payara Platform Payara Server (Admin Console modules) allows Remote Code Inclusion.This issue affects Payara Server: from 5.20.0 before 5.68.0, from 6.0.0 before 6.19.0, from 6.2022.1 before 6.2024.10, from 4.1.2.191.1 before 4.1.2.191.51.
Affected products
- Payara Payara: from 4.1.2.191, before 4.1.2.191.51 (fixed in 4.1.2.191.51); from 5.20.0, before 5.68.0 (fixed in 5.68.0); from 6.0.0, up to and including 6.19.0; from 6.2022.1, before 6.2024.10 (fixed in 6.2024.10)
Published 2024-10-08. Last modified 2026-06-17.