CVE-2024-45687
LOWPayara Platform <6.21.0 - HTTP Request/Response Splitting
Title source: llmDescription
Improper Neutralization of CRLF Sequences in HTTP Headers ('HTTP Request/Response Splitting') vulnerability in Payara Platform Payara Server (Grizzly, REST Management Interface modules), Payara Platform Payara Micro (Grizzly modules) allows Manipulating State, Identity Spoofing.This issue affects Payara Server: from 4.1.151 through 4.1.2.191.51, from 5.20.0 through 5.70.0, from 5.2020.2 through 5.2022.5, from 6.2022.1 through 6.2024.12, from 6.0.0 through 6.21.0; Payara Micro: from 4.1.152 through 4.1.2.191.51, from 5.20.0 through 5.70.0, from 5.2020.2 through 5.2022.5, from 6.2022.1 through 6.2024.12, from 6.0.0 through 6.21.0.
References (3)
Core 3
Core References
Various Sources release-notes
https://docs.payara.fish/enterprise/docs/Release%20Notes/Release%20Notes%206.22.0.html
Various Sources release-notes
https://docs.payara.fish/enterprise/docs/5.71.0/Release%20Notes/Release%20Notes%205.71.0.html
Various Sources release-notes
https://docs.payara.fish/community/docs/6.2025.1/Release%20Notes/Release%20Notes%206.2025.1.html
Scores
CVSS v4
2.4
EPSS
0.0022
EPSS Percentile
11.9%
CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:A/VC:L/VI:N/VA:N/SC:L/SI:N/SA:N/S:N
CISA SSVC
Vulnrichment
Exploitation
none
Automatable
no
Technical Impact
partial
Details
CWE
CWE-113
Status
published
Products (10)
Payara Platform/Payara Micro
4.1.152 - 4.1.2.191.51
Payara Platform/Payara Micro
5.20.0 - 5.70.0
Payara Platform/Payara Micro
5.2020.2 - 5.2022.5
Payara Platform/Payara Micro
6.0.0 - 6.21.0
Payara Platform/Payara Micro
6.2022.1 - 6.2024.12
Payara Platform/Payara Server
4.1.151 - 4.1.2.191.51
Payara Platform/Payara Server
5.20.0 - 5.70.0
Payara Platform/Payara Server
5.2020.2 - 5.2022.5
Payara Platform/Payara Server
6.0.0 - 6.21.0
Payara Platform/Payara Server
6.2022.1 - 6.2024.12
Published
Jan 21, 2025
Tracked Since
Feb 18, 2026