Payara, when deployed to the root context, allows attackers to visit META-INF and WEB-INF
High severity
GitHub Reviewed
Published
Nov 10, 2022
to the GitHub Advisory Database
•
Updated Sep 4, 2025
Package
Affected versions
>= 6.2021.1.Alpha1, < 6.2022.2
>= 5.0.0.Alpha1, < 5.2022.2
<= 4.1.2.181
Patched versions
6.2022.2
5.2022.5
Description
Published by the National Vulnerability Database
Nov 10, 2022
Published to the GitHub Advisory Database
Nov 10, 2022
Reviewed
Sep 4, 2025
Last updated
Sep 4, 2025
Payara before 2022-11-04, when deployed to the root context, allows attackers to visit META-INF and WEB-INF, a different vulnerability than CVE-2022-37422. This affects Payara Platform Community before 4.1.2.191.38, 5.x before 5.2022.4, and 6.x before 6.2022.1, and Payara Platform Enterprise before 5.45.0.
References