CVE Feed

    Dashboard / CVE / CVE-2023-28462

    CVE-2023-28462

    A JNDI rebind operation in the default ORB listener in Payara Server 4.1.2.191 (Enterprise), 5.20.0 and newer (Enterprise), and 5.2020.1 and newer (Community), when Java 1.8u181 and earlier is used, allows remote attackers to load malicious code on the server once a JNDI directory scan is performed.

    Published:Mar 30, 2023
    Last Modified:Feb 18, 2025
    EPS:Mar 30, 2023
    EPSS Score:0.01345
    CVSS Score:9.8

    Affected Products

    Vendor
    Oracle
    Product
    Jdk
    Vendor
    Payara
    Product
    Payara Server

    Exploits

    No exploit reference

    Common Attack Pattern Enumeration and Classification (CAPEC)

    Related CVEs

    Common Vulnerability Scoring System

    Attack Vector
    Network
    Adjacent
    Local
    Physical
    Privileges Required
    None
    Low
    High
    User Interaction
    None
    Required
    Scope
    Unchanged
    Changed
    Confidentiality
    None
    Low
    High
    Integrity
    None
    Low
    High
    Availability
    None
    Low
    High