Vulnerability Description
A JNDI rebind operation in the default ORB listener in Payara Server 4.1.2.191 (Enterprise), 5.20.0 and newer (Enterprise), and 5.2020.1 and newer (Community), when Java 1.8u181 and earlier is used, allows remote attackers to load malicious code on the server once a JNDI directory scan is performed.
CVSS Score
CRITICAL
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Payara | Payara Server | >= 4.1.2.191, <= 5.0.0 |
| Oracle | Jdk | 1.8.0 |
Related Weaknesses (CWE)
References
- https://blog.payara.fish/vulnerability-affecting-server-environments-on-java-1.8MitigationVendor Advisory
- https://blog.payara.fish/vulnerability-affecting-server-environments-on-java-1.8MitigationVendor Advisory
FAQ
What is CVE-2023-28462?
CVE-2023-28462 is a vulnerability with a CVSS score of 9.8 (CRITICAL). A JNDI rebind operation in the default ORB listener in Payara Server 4.1.2.191 (Enterprise), 5.20.0 and newer (Enterprise), and 5.2020.1 and newer (Community), when Java 1.8u181 and earlier is used, a...
How severe is CVE-2023-28462?
CVE-2023-28462 has been rated CRITICAL with a CVSS base score of 9.8/10. This is considered a critical vulnerability requiring immediate attention.
Is there a patch for CVE-2023-28462?
Check the references section above for vendor advisories and patch information. Affected products include: Payara Payara Server, Oracle Jdk.