CVE-2024-45687

LOW

Payara Platform <6.21.0 - HTTP Request/Response Splitting

Title source: llm
STIX 2.1

Description

Improper Neutralization of CRLF Sequences in HTTP Headers ('HTTP Request/Response Splitting') vulnerability in Payara Platform Payara Server (Grizzly, REST Management Interface modules), Payara Platform Payara Micro (Grizzly modules) allows Manipulating State, Identity Spoofing.This issue affects Payara Server: from 4.1.151 through 4.1.2.191.51, from 5.20.0 through 5.70.0, from 5.2020.2 through 5.2022.5, from 6.2022.1 through 6.2024.12, from 6.0.0 through 6.21.0; Payara Micro: from 4.1.152 through 4.1.2.191.51, from 5.20.0 through 5.70.0, from 5.2020.2 through 5.2022.5, from 6.2022.1 through 6.2024.12, from 6.0.0 through 6.21.0.

Scores

CVSS v4 2.4
EPSS 0.0022
EPSS Percentile 44.6%
CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:A/VC:L/VI:N/VA:N/SC:L/SI:N/SA:N/S:N

CISA SSVC

Vulnrichment
Exploitation none
Automatable no
Technical Impact partial

Details

CWE
CWE-113
Status published
Products (10)
Payara Platform/Payara Micro 4.1.152 - 4.1.2.191.51
Payara Platform/Payara Micro 5.20.0 - 5.70.0
Payara Platform/Payara Micro 5.2020.2 - 5.2022.5
Payara Platform/Payara Micro 6.0.0 - 6.21.0
Payara Platform/Payara Micro 6.2022.1 - 6.2024.12
Payara Platform/Payara Server 4.1.151 - 4.1.2.191.51
Payara Platform/Payara Server 5.20.0 - 5.70.0
Payara Platform/Payara Server 5.2020.2 - 5.2022.5
Payara Platform/Payara Server 6.0.0 - 6.21.0
Payara Platform/Payara Server 6.2022.1 - 6.2024.12
Published Jan 21, 2025
Tracked Since Feb 18, 2026