CVE-2024-45687
HTTP Server incorrectly accepting disallowed characters within header values
Severity Score
2.4
*CVSS v4
Exploit Likelihood
*EPSS
Affected Versions
*CPE
Public Exploits
0
*Multiple Sources
Exploited in Wild
-
*KEV
Decision
Track
*SSVC
Descriptions
Improper Neutralization of CRLF Sequences in HTTP Headers ('HTTP Request/Response Splitting') vulnerability in Payara Platform Payara Server (Grizzly, REST Management Interface modules), Payara Platform Payara Micro (Grizzly modules) allows Manipulating State, Identity Spoofing.This issue affects Payara Server: from 4.1.151 through 4.1.2.191.51, from 5.20.0 through 5.70.0, from 5.2020.2 through 5.2022.5, from 6.2022.1 through 6.2024.12, from 6.0.0 through 6.21.0; Payara Micro: from 4.1.152 through 4.1.2.191.51, from 5.20.0 through 5.70.0, from 5.2020.2 through 5.2022.5, from 6.2022.1 through 6.2024.12, from 6.0.0 through 6.21.0.
*Credits:
Ben Kallus
CVSS Scores
Attack Vector
Attack Complexity
Attack Requirements
Privileges Required
User Interaction
System
Vulnerable | Subsequent
Confidentiality
Integrity
Availability
Attack Vector
Attack Complexity
Attack Requirements
Privileges Required
User Interaction
System
Vulnerable | Subsequent
Confidentiality
Integrity
Availability
Attack Vector
Attack Complexity
Privileges Required
User Interaction
Scope
Confidentiality
Integrity
Availability
Attack Vector
Attack Complexity
Authentication
Confidentiality
Integrity
Availability
* Common Vulnerability Scoring System
SSVC
- Decision:Track
Exploitation
Automatable
Tech. Impact
* Organization's Worst-case Scenario
Timeline
- 2024-09-04 CVE Reserved
- 2025-01-21 CVE Published
- 2025-02-12 CVE Updated
- 2025-05-23 EPSS Updated
- ---------- Exploited in Wild
- ---------- KEV Due Date
- ---------- First Exploit
CWE
- CWE-113: Improper Neutralization of CRLF Sequences in HTTP Headers ('HTTP Request/Response Splitting')
CAPEC
- CAPEC-74: Manipulating State
- CAPEC-151: Identity Spoofing
References (3)
URL | Date | SRC |
---|
URL | Date | SRC |
---|
URL | Date | SRC |
---|
Affected Vendors, Products, and Versions
Vendor | Product | Version | Other | Status | ||||||
---|---|---|---|---|---|---|---|---|---|---|
Vendor | Product | Version | Other | Status | <-- --> | Vendor | Product | Version | Other | Status |
Payara Platform Search vendor "Payara Platform" | Payara Server Search vendor "Payara Platform" for product "Payara Server" | >= 4.1.2.191.51 <= 4.1.151.0.0 Search vendor "Payara Platform" for product "Payara Server" and version " >= 4.1.2.191.51 <= 4.1.151.0.0" | en |
Affected
| ||||||
Payara Platform Search vendor "Payara Platform" | Payara Server Search vendor "Payara Platform" for product "Payara Server" | >= 5.20.0 <= 5.70.0 Search vendor "Payara Platform" for product "Payara Server" and version " >= 5.20.0 <= 5.70.0" | en |
Affected
| ||||||
Payara Platform Search vendor "Payara Platform" | Payara Server Search vendor "Payara Platform" for product "Payara Server" | >= 5.2020.2 <= 5.2022.5 Search vendor "Payara Platform" for product "Payara Server" and version " >= 5.2020.2 <= 5.2022.5" | en |
Affected
| ||||||
Payara Platform Search vendor "Payara Platform" | Payara Server Search vendor "Payara Platform" for product "Payara Server" | >= 6.2022.1 <= 6.2024.12 Search vendor "Payara Platform" for product "Payara Server" and version " >= 6.2022.1 <= 6.2024.12" | en |
Affected
| ||||||
Payara Platform Search vendor "Payara Platform" | Payara Server Search vendor "Payara Platform" for product "Payara Server" | >= 6.0.0 <= 6.21.0 Search vendor "Payara Platform" for product "Payara Server" and version " >= 6.0.0 <= 6.21.0" | en |
Affected
| ||||||
Payara Platform Search vendor "Payara Platform" | Payara Micro Search vendor "Payara Platform" for product "Payara Micro" | >= 4.1.2.191.51 <= 4.1.152.0.0 Search vendor "Payara Platform" for product "Payara Micro" and version " >= 4.1.2.191.51 <= 4.1.152.0.0" | en |
Affected
| ||||||
Payara Platform Search vendor "Payara Platform" | Payara Micro Search vendor "Payara Platform" for product "Payara Micro" | >= 5.20.0 <= 5.70.0 Search vendor "Payara Platform" for product "Payara Micro" and version " >= 5.20.0 <= 5.70.0" | en |
Affected
| ||||||
Payara Platform Search vendor "Payara Platform" | Payara Micro Search vendor "Payara Platform" for product "Payara Micro" | >= 5.2020.2 <= 5.2022.5 Search vendor "Payara Platform" for product "Payara Micro" and version " >= 5.2020.2 <= 5.2022.5" | en |
Affected
| ||||||
Payara Platform Search vendor "Payara Platform" | Payara Micro Search vendor "Payara Platform" for product "Payara Micro" | >= 6.2022.1 <= 6.2024.12 Search vendor "Payara Platform" for product "Payara Micro" and version " >= 6.2022.1 <= 6.2024.12" | en |
Affected
| ||||||
Payara Platform Search vendor "Payara Platform" | Payara Micro Search vendor "Payara Platform" for product "Payara Micro" | >= 6.0.0 <= 6.21.0 Search vendor "Payara Platform" for product "Payara Micro" and version " >= 6.0.0 <= 6.21.0" | en |
Affected
|