Browse all 7 CVE security advisories affecting Payara Platform. AI-powered Chinese analysis, POCs, and references for each vulnerability.
Payara Platform serves as an enterprise-grade Java application server and cloud-native runtime for developing and deploying Java EE and Jakarta EE applications. Historically, it has been susceptible to remote code execution, cross-site scripting, and privilege escalation vulnerabilities, often stemming from misconfigurations or insecure default settings. The platform maintains a moderate security posture with 7 current CVEs, primarily related to authentication bypasses and information disclosure. While no major security incidents have been widely documented, regular security updates and hardening are recommended due to its exposure to common web application threats. Payara Platform's security focus includes built-in monitoring and the Open Web Application Security Project (OWASP) compliance features to mitigate risks in production environments.
| CVE ID | Title | CVSS | Severity | Published |
|---|---|---|---|---|
| CVE-2025-14340 | Admin Account Takeover via malicious URL payload — Payara ServerCWE-79 | 6.1AI | MediumAI | 2026-02-18 |
| CVE-2025-1534 | Cross-site Scripting (Stored) — Payara Server | 6.1AI | MediumAI | 2025-04-01 |
| CVE-2024-45687 | HTTP Server incorrectly accepting disallowed characters within header values — Payara ServerCWE-113 | 6.5 | - | 2025-01-21 |
| CVE-2024-8215 | Payload Injection Attack via Management REST interface — Payara ServerCWE-79 | 9.6AI | CriticalAI | 2024-10-08 |
| CVE-2024-8097 | Sensitive information exposure when the org.glassfish.admingui LOGGER is set to FINEST level — Payara ServerCWE-200 | 6.5AI | MediumAI | 2024-09-11 |
| CVE-2024-7312 | REST Interface Link Redirection via Host parameter — Payara ServerCWE-601 | 6.1AI | MediumAI | 2024-09-11 |
| CVE-2023-41699 | Payara Platform: URL Redirection to untrusted site using FORM authentication — Payara Server, Micro and EmbeddedCWE-601 | 6.1 | Medium | 2023-11-15 |
This page lists every published CVE security advisory associated with Payara Platform. Each entry links to a detailed page with CVSS scoring, CWE classification, affected products and references. AI-generated Chinese analysis is provided for fast triage.