First published: Tue Apr 01 2025(Updated: )
CVE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Payara Platform Payara Server allows : Remote Code Inclusion.This issue affects Payara Server: from 4.1.2.1919.1 before 4.1.2.191.51, from 5.20.0 before 5.68.0, from 6.0.0 before 6.23.0, from 6.2022.1 before 6.2025.2.
Credit: 769c9ae7-73c3-4e47-ae19-903170fc3eb8
Affected Software | Affected Version | How to fix |
---|---|---|
Payara Server | >=4.1.2.1919.1<4.1.2.191.51>=5.20.0<5.68.0>=6.0.0<6.23.0>=6.2022.1<6.2025.2 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2025-1534 has a high severity rating due to its potential for Remote Code Inclusion.
To mitigate CVE-2025-1534, upgrade Payara Server to version 4.1.2.191.51 or later, 5.68.0 or later, or 6.23.0 or later.
CVE-2025-1534 affects Payara Server versions from 4.1.2.1919.1 to 4.1.2.191.51, 5.20.0 to 5.68.0, and 6.0.0 to 6.23.0.
CVE-2025-1534 is an Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability.
Yes, CVE-2025-1534 can potentially lead to data breaches through Remote Code Inclusion if exploited.