Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1336 CNY

100%

CVE-2022-37422 PoC — Payara 路径遍历漏洞

Source
Associated Vulnerability
Title: Payara 路径遍历漏洞 (CVE-2022-37422)
Description:Payara through 5.2022.2 allows directory traversal without authentication. This affects Payara Server, Payara Micro, and Payara Server Embedded.
Readme
![#badassfish](payara-logo-blue.png)

# Payara Platform Community Edition

**Create. Innovate. Elevate.**

Payara Platform Community Edition features open source server runtimes for development projects and containerized Jakarta EE and MicroProfile applications.

**Payara Server Community** is a cloud-native, innovative open source middleware platform for development projects that supports Jakarta EE (Java EE) applications in any environment: on premise, in the cloud or hybrid.

**Payara Micro Community** is the open source, lightweight middleware platform of choice for containerized Jakarta EE (Java EE) microservices deployments in development. Less than 70MB, Payara Micro requires no installation, configuration or code rewrites.

Visit [www.payara.fish](http://www.payara.fish/ "http://www.payara.fish/") for free resources and information about the stable and fully supported [Payara Enterprise Edition](https://www.payara.fish/enterprise/ "https://www.payara.fish/enterprise/"), designed for mission critical systems in production including 24x7, 10x5, and Migration & Project Support options.

Access the complete Payara Server and Payara Micro documentation:

[https://docs.payara.fish](https://docs.payara.fish/ "https://docs.payara.fish/")

## Payara Platform Community

**Helps you Innovate:**

-   Rapid access to new features

-   Regular & frequent releases

-   Software experimentation

-   Suitable for development projects

**Offers Community-based Support:**

-   Get assistance on Payara Forum

-   Raise bugs on GitHub

-   Tech Blog

-   User guides & datasheets

-----------------------

Payara<sup>&reg;</sup> is a trademark of the Payara Foundation.

GlassFish<sup>&reg;</sup> is a trademark of the Eclipse Foundation.
File Snapshot

Log in to view the POC file snapshot cached by Shenlong Bot

Log in to view
Remarks
    1. It is advised to access via the original source first.
    2. Local POC snapshots are reserved for subscribers — if the original source is unavailable, the local mirror is part of the paid plan.
    3. Mirroring, verifying, and maintaining this POC archive takes ongoing effort, so local snapshots are a paid feature. Your subscription keeps the archive online — thank you for the support. View subscription plans →