9.8
CVSSv3

CVE-2023-28462

Published: 30/03/2023 Updated: 07/04/2023
CVSS v3 Base Score: 9.8 | Impact Score: 5.9 | Exploitability Score: 3.9
VMScore: 0

Vulnerability Summary

A JNDI rebind operation in the default ORB listener in Payara Server 4.1.2.191 (Enterprise), 5.20.0 and newer (Enterprise), and 5.2020.1 and newer (Community), when Java 1.8u181 and previous versions is used, allows remote malicious users to load malicious code on the server once a JNDI directory scan is performed.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

payara payara_server