Payara before 2022-11-04, when deployed to the root context, allows attackers to visit META-INF and WEB-INF, a different vulnerability than CVE-2022-37422. This affects Payara Platform Community before 4.1.2.191.38, 5.x before 5.2022.4, and 6.x before 6.2022.1, and Payara Platform Enterprise before 5.45.0.
Metrics
Affected Vendors & Products
Advisories
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2022-48046 | Payara before 2022-11-04, when deployed to the root context, allows attackers to visit META-INF and WEB-INF, a different vulnerability than CVE-2022-37422. This affects Payara Platform Community before 4.1.2.191.38, 5.x before 5.2022.4, and 6.x before 6.2022.1, and Payara Platform Enterprise before 5.45.0. |
Github GHSA |
GHSA-q35w-85pq-rv3x | Payara, when deployed to the root context, allows attackers to visit META-INF and WEB-INF |
Fixes
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
References
History
Fri, 02 May 2025 20:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Status: PUBLISHED
Assigner: mitre
Published:
Updated: 2025-05-01T13:42:02.196Z
Reserved: 2022-11-10T00:00:00.000Z
Link: CVE-2022-45129
Updated: 2024-08-03T14:01:31.594Z
Status : Modified
Published: 2022-11-10T06:15:13.813
Modified: 2025-05-01T14:15:33.720
Link: CVE-2022-45129
No data.
OpenCVE Enrichment
No data.
EUVD
Github GHSA