← Back

CVE-2023-28462

nvd nist
Published: Mar 30, 2023Modified: Jun 17, 2026

JSON object

Loading...
9.8
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Exploitability: 3.9 / Impact: 5.9
Source: NVD

Description

A JNDI rebind operation in the default ORB listener in Payara Server 4.1.2.191 (Enterprise), 5.20.0 and newer (Enterprise), and 5.2020.1 and newer (Community), when Java 1.8u181 and earlier is used, allows remote attackers to load malicious code on the server once a JNDI directory scan is performed.

Affected (3)

1 product
Payara Server
Configuration A
3 vulnerable · 1 platform
Vulnerable SoftwareAffected Versions
Payara
From 5.2020.1
From 4.1.2.191 to 5.0.0
From 5.20.0
Running on/withPlatform Versions
Oracle
Jdk
Version 1.8.0 update181

Timeline

No history available yet.