High severity8.4NVD Advisory· Published Oct 8, 2024· Updated Jun 17, 2026
CVE-2024-8215
CVE-2024-8215
Description
Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Payara Platform Payara Server (Admin Console modules) allows Remote Code Inclusion.This issue affects Payara Server: from 5.20.0 before 5.68.0, from 6.0.0 before 6.19.0, from 6.2022.1 before 6.2024.10, from 4.1.2.191.1 before 4.1.2.191.51.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
5cpe:2.3:a:payara:payara:*:*:*:*:community:*:*:*+ 1 more
- cpe:2.3:a:payara:payara:*:*:*:*:community:*:*:*range: >=4.1.2.191,<4.1.2.191.51
- cpe:2.3:a:payara:payara:*:*:*:*:enterprise:*:*:*range: >=5.20.0,<5.68.0
5.20.0+ 1 more
- (no CPE)range: 5.20.0
- (no CPE)range: from 5.20.0 before 5.68.0, from 6.0.0 before 6.19.0, from 6.2022.1 before 6.2024.10, from 4.1.2.191.1 before 4.1.2.191.51
- Range: from 5.20.0 before 5.68.0, from 6.0.0 before 6.19.0, from 6.2022.1 before 6.2024.10, from 4.1.2.191.1 before 4.1.2.191.51
Patches
Vulnerability mechanics
References
3News mentions
0No linked articles in our index yet.