CVE-2024-8215: Payload Injection Attack via Management REST interface
Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Payara Platform Payara Server (Admin Console modules) allows Remote Code Inclusion.This issue affects Payara Server: from 5.20.0 before 5.68.0, from 6.0.0 before 6.19.0, from 6.2022.1 before 6.2024.10, from 4.1.2.191.1 before 4.1.2.191.51.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2024-8215?
CVE-2024-8215 is classified as a high severity vulnerability due to its potential for Remote Code Inclusion through Cross-site Scripting.
How do I fix CVE-2024-8215?
To mitigate CVE-2024-8215, upgrade Payara Server to versions 5.68.0 or later for the enterprise edition and 6.19.0 or later for the community edition.
Which versions of Payara Server are affected by CVE-2024-8215?
CVE-2024-8215 affects Payara Server versions from 5.20.0 before 5.68.0, 6.0.0 before 6.19.0, and versions of the community edition from 4.1.2 to 4.1.2.191.
What type of vulnerability is CVE-2024-8215?
CVE-2024-8215 is an Improper Neutralization of Input During Web Page Generation, specifically related to Cross-site Scripting (XSS).
Can CVE-2024-8215 allow attackers to execute code remotely?
Yes, CVE-2024-8215 can allow attackers to perform Remote Code Inclusion, escalating the risk of remote code execution.