VYPR
High severity7.5NVD Advisory· Published Aug 18, 2022· Updated Jun 17, 2026

CVE-2022-37422

CVE-2022-37422

Description

Payara through 5.2022.2 allows directory traversal without authentication. This affects Payara Server, Payara Micro, and Payara Server Embedded.

AI Insight

LLM-synthesized narrative grounded in this CVE's description and references.

Affected packages

Versions sourced from the GitHub Security Advisory.

PackageAffected versionsPatched versions
fish.payara.api:payara-bomMaven
< 5.2022.35.2022.3

Affected products

4
  • cpe:2.3:a:payara:payara:*:*:*:*:community:*:*:*+ 2 more
    • cpe:2.3:a:payara:payara:*:*:*:*:community:*:*:*range: <5.2022.3
    • cpe:2.3:a:payara:payara:*:*:*:*:enterprise:*:*:*range: <4.1.2.191.36
    • (no CPE)
  • ghsa-coords
    Range: < 5.2022.3

Patches

Vulnerability mechanics

References

4

News mentions

0

No linked articles in our index yet.