Critical severity9.8NVD Advisory· Published Mar 30, 2023· Updated Jun 17, 2026
CVE-2023-28462
CVE-2023-28462
Description
A JNDI rebind operation in the default ORB listener in Payara Server 4.1.2.191 (Enterprise), 5.20.0 and newer (Enterprise), and 5.2020.1 and newer (Community), when Java 1.8u181 and earlier is used, allows remote attackers to load malicious code on the server once a JNDI directory scan is performed.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected packages
Versions sourced from the GitHub Security Advisory.
| Package | Affected versions | Patched versions |
|---|---|---|
fish.payara.server:payara-aggregatorMaven | >= 5.2020.1, < 6.2022.1.Alpha3 | 6.2022.1.Alpha3 |
Affected products
4cpe:2.3:a:payara:payara_server:*:*:*:*:enterprise:*:*:*+ 2 more
- cpe:2.3:a:payara:payara_server:*:*:*:*:enterprise:*:*:*range: >=4.1.2.191,<=5.0.0
- cpe:2.3:a:payara:payara_server:*:*:*:*:community:*:*:*range: >=5.2020.1
- (no CPE)
Patches
Vulnerability mechanics
References
3- blog.payara.fish/vulnerability-affecting-server-environments-on-java-1.8-on-updates-lower-than-1.8u191nvdMitigationVendor AdvisoryWEB
- github.com/advisories/GHSA-xc93-587g-mxm7ghsaADVISORY
- nvd.nist.gov/vuln/detail/CVE-2023-28462ghsaADVISORY
News mentions
0No linked articles in our index yet.