Description


A JNDI rebind operation in the default ORB listener in Payara Server 4.1.2.191 (Enterprise), 5.20.0 and newer (Enterprise), and 5.2020.1 and newer (Community), when Java 1.8u181 and earlier is used, allows remote attackers to load malicious code on the server once a JNDI directory scan is performed.

Related CPE's


a

payara

payara_server

3

Weaknesses



NVD-CWE-noinfo

134c704f-9b21-4f2e-91b3-4a467353bcc0

Secondary

CWE-502

CVSS impact metrics


CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

9.8 · Critical

Information


Source identifier

[email protected]

Vulnerability status

Modified

Published

2023-03-30T18:15:07.733Z

2 years ago

Last modified

2025-02-18T18:15:11.523Z

1 year ago