CVE-2022-45129: High severity Payara Payara vulnerability
Payara before 2022-11-04, when deployed to the root context, allows attackers to visit META-INF and WEB-INF, a different vulnerability than CVE-2022-37422. This affects Payara Platform Community before 4.1.2.191.38, 5.x before 5.2022.4, and 6.x before 6.2022.1, and Payara Platform Enterprise before 5.45.0.
Affected Software
Remediation
Event History
Frequently Asked Questions
What is the vulnerability ID?
The vulnerability ID is CVE-2022-45129.
What is the severity of CVE-2022-45129?
The severity of CVE-2022-45129 is high (7.5).
Which software versions are affected by CVE-2022-45129?
Payara Platform Community before 4.1.2.191.38, 5.x before 5.2022.4, and 6.x before 6.2022.1, and Payara Platform Enterprise before 5.45.0 are affected.
How can attackers exploit CVE-2022-45129?
Attackers can visit META-INF and WEB-INF by deploying Payara to the root context.
Is there a fix for CVE-2022-45129?
Yes, updating to Payara Platform Community 4.1.2.191.38, 5.2022.4, or 6.2022.1, or Payara Platform Enterprise 5.45.0 will fix the vulnerability.