First published: Tue Oct 08 2024(Updated: )
Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Payara Platform Payara Server (Admin Console modules) allows Remote Code Inclusion.This issue affects Payara Server: from 5.20.0 before 5.68.0, from 6.0.0 before 6.19.0, from 6.2022.1 before 6.2024.10, from 4.1.2.191.1 before 4.1.2.191.51.
Credit: 769c9ae7-73c3-4e47-ae19-903170fc3eb8
Affected Software | Affected Version | How to fix |
---|---|---|
Payara Payara | >=4.1.2.191<4.1.2.191.51 | |
Payara Payara | >=5.20.0<5.68.0 | |
Payara Payara | >=6.0.0<=6.19.0 | |
Payara Payara | >=6.2022.1<6.2024.10 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2024-8215 is classified as a high severity vulnerability due to its potential for Remote Code Inclusion through Cross-site Scripting.
To mitigate CVE-2024-8215, upgrade Payara Server to versions 5.68.0 or later for the enterprise edition and 6.19.0 or later for the community edition.
CVE-2024-8215 affects Payara Server versions from 5.20.0 before 5.68.0, 6.0.0 before 6.19.0, and versions of the community edition from 4.1.2 to 4.1.2.191.
CVE-2024-8215 is an Improper Neutralization of Input During Web Page Generation, specifically related to Cross-site Scripting (XSS).
Yes, CVE-2024-8215 can allow attackers to perform Remote Code Inclusion, escalating the risk of remote code execution.