CVE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Payara Platform Payara Server allows : Remote Code Inclusion.This issue affects Payara Server: from 4.1.2.1919.1 before 4.1.2.191.51, from 5.20.0 before 5.68.0, from 6.0.0 before 6.23.0, from 6.2022.1 before 6.2025.2.
Metrics
Affected Vendors & Products
References
History
Tue, 14 Oct 2025 17:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Payara
Payara payara |
|
| CPEs | cpe:2.3:a:payara:payara:*:*:*:*:community:*:*:* cpe:2.3:a:payara:payara:*:*:*:*:enterprise:*:*:* |
|
| Vendors & Products |
Payara
Payara payara |
|
| Metrics |
cvssV3_1
|
Mon, 07 Apr 2025 21:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| References |
|
Thu, 03 Apr 2025 18:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Weaknesses | CWE-79 |
Tue, 01 Apr 2025 15:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Tue, 01 Apr 2025 03:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | CVE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Payara Platform Payara Server allows : Remote Code Inclusion.This issue affects Payara Server: from 4.1.2.1919.1 before 4.1.2.191.51, from 5.20.0 before 5.68.0, from 6.0.0 before 6.23.0, from 6.2022.1 before 6.2025.2. | |
| Title | Cross-site Scripting (Stored) | |
| References |
| |
| Metrics |
cvssV4_0
|
Status: PUBLISHED
Assigner: Payara
Published: 2025-04-01T03:25:30.153Z
Updated: 2025-04-07T20:59:19.493Z
Reserved: 2025-02-21T03:16:53.650Z
Link: CVE-2025-1534
Updated: 2025-04-01T14:12:53.676Z
Status : Analyzed
Published: 2025-04-01T04:15:44.170
Modified: 2025-10-14T17:25:28.423
Link: CVE-2025-1534
No data.