Vulnerability record · CVE-2021-41381 · published 23 September 2021
CVE-2021-41381: Payara Micro Community directory traversal allows file read
Payara · Micro Community
Payara Micro Community 5.2021.6 and earlier is vulnerable to directory traversal (CWE-22), letting a remote unauthenticated attacker request files outside the intended web root. The flaw is trivially reachable over the network and public proof-of-concept code exists, so exposed instances should be treated as at risk of information disclosure.
Description
Payara Micro Community 5.2021.6 and below allows Directory Traversal.
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
Automated analysis
high priorityRemote unauthenticated file read with public exploit code and a high EPSS score, though no KEV listing or evidence of active mass exploitation.
What it is
Payara Micro Community 5.2021.6 and earlier is vulnerable to directory traversal (CWE-22), letting a remote unauthenticated attacker request files outside the intended web root. The flaw is trivially reachable over the network and public proof-of-concept code exists, so exposed instances should be treated as at risk of information disclosure.
Impact
An attacker can read arbitrary files on the server that the Payara process can access, potentially exposing configuration, credentials and application data. There is no evidence in the record of code execution or data modification.
Attack surface
Reached over the network via HTTP requests to the affected Payara Micro Community service; the CVSS vector shows no privileges and no user interaction required. Any instance exposed to untrusted networks is directly reachable.
Exploitation
Not listed in CISA KEV, but EPSS is high (0.529, ~98.9th percentile) and multiple references are tagged Exploit, including Exploit-DB and Packet Storm entries, indicating public exploit code is available.
What to do
- Upgrade Payara Micro Community to a version later than 5.2021.6; the record does not name a fixed version, so confirm the patched release with the vendor.
- If immediate upgrade is not possible, restrict network access to the Payara service with firewall rules or a reverse proxy that normalizes and rejects traversal sequences.
- Run the service with least-privilege filesystem permissions so a traversal read cannot reach sensitive files.
- Review the vendor advisory and SYSS-2021-054 for any configuration hardening guidance.
- Monitor vendor channels for updated fixed versions since the record does not specify one.
Detection
- Inspect web and proxy logs for requests containing ../, encoded traversal sequences (%2e%2e, ..%2f) or absolute paths targeting the Payara service.
- Alert on HTTP responses returning files outside expected static content paths, especially configuration or credential files.
- Baseline normal request URI patterns for the application and flag anomalies.
- Correlate outbound or internal file access events from the Payara process with unusual request sources.
This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.
Affected products
1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.
References
Track CVE-2021-41381 inside VULONE
Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.
Related vulnerabilities
Same products first, then exploited flaws of the same weakness class.
Source: NIST National Vulnerability Database (record CVE-2021-41381), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.