Security in the Payara Platform

Security is always a concern when implementing applications that will run in production environments. The Payara Platform Enterprise is a fully-supported open source software for enterprises offering a strong tool set of security features so you won’t have to implement your own security measures from scratch,  enabling reliable and secure deployments of Jakarta EE and MicroProfile applications on premises, in the cloud, or hybrid environments.

Making the platform secure and providing useful built-in security tools for application developers and production administrators is an essential part of the platform development process and is accomplished with monthly releases, security fixes, critical security patches, and a 10-year software lifecycle. The Payara Platform also provides tools to secure and restrict access to a production system, encrypt communication, and audit security events and configuration changes.

Payara Server and Docker

Security Auditing in Payara Server

This guide explains and demonstrates the security auditing best practises and features you can find in Payara Server. Security is always a concern you must have when implementing applications that will run in production environments. Both the JVM and Payara Server have a strong tool set of security implementations for most use cases in the industry.

Securing Your Applications Running on Payara Platform (JAX-RS Endpoints)

This User Guide will discuss the different aspects of securing the JAX-RS endpoints of your application using standards and common practices like OAuth2, OpenID Connect, JWT Tokens, and MicroProfile JWT authentication in combination with the Payara Platform.

Security Tools in Payara Platform

In this datasheet learn about the tools provided by the Payara Platform to secure and restrict access to a production system, encrypt communication, and audit security events and configuration changes.

How to Develop Applications with Minimal Security Risks

This user guide written in collaboration with Snyk, takes you through 7 key pointers for developing applications with a minimal security risk. It will help you take responsibility for the security of your software, to best avoid becoming one of the 20,000 websites every day that get hacked on average.

How to Raise Security Issues

Payara Services Limited is very active at identifying and fixing possible security vulnerabilities included into Payara Server and Payara Micro that are either inherited from GlassFish upstream or introduced by new features developed.

We strongly encourage users to report such problems in the following ways:

  1. If you have a support contract, create a ticket describing the security vulnerabilities detected as you would do for any other bug reports.
  2. If you do not have a support contract, please send an email with the described vulnerabilities detected to security@payara.fishPlease don’t use this address to report bugs or issues unrelated to security vulnerabilities as they will be ignored, instead use the GitHub repository issues page for raising a new issue detailing the problem at hand.

You can also direct inquiries about reported CVE issues detected in similar Java platforms or application servers (like Apache Tomcat, JBoss WildFly, etc.) and let us research whether or not Payara Server is affected by such issues.

security-shield

Discover More Resources

Explore expert tips, webinars, and product updates to help you build, deploy, and scale modern enterprise Java applications faster.

Payara Enterprise Migration & Project Support Option datasheet
Datasheet

Payara Enterprise Migration & Project Support Option

Using Payara Platform Enterprise gives you additional reassurance that your production systems are secured and safe Payara Platform also […]

Download
The Busy CTO’s Guide to Java Application Security Risks
User Guide

The Busy CTO’s Guide to Java Application Security Risks

Identify Risks. Strengthen Compliance. Safeguard Java. Java applications are under pressure in 2025. With 88% of enterprise apps containing […]

Download
Securing Jakarta EE (Java EE) Application Servers: An Executive Guide
User Guide

Securing Jakarta EE (Java EE) Application Servers: An Executive Guide

Identify Vulnerabilities. Harden Servers. Safeguard Enterprise Java. Jakarta EE (Java EE) application servers remain a critical backbone for enterprise […]

Download

Security Video Tutorials

MicroProfile in Practice – Expose and visualise metrics, Configure your app & Secure REST endpoints.

Java Champion Ondrej Mihalyi demonstrates with a simple game application, some MicroProfile capabilities in the Payara Platform which powers both Payara Server and Payara Micro. Demonstrating how to:

  • Expose operational and business logic metrics and how to visualise them.
  • Configure your applications.
  • Secure REST endpoints in your applications using JSON web token mechanism.
MicroProfile in Practice – Expose and visualise metrics, Configure your app & Secure REST endpoints.

This User Guide will discuss the different aspects of securing the JAX-RS endpoints of your application using standards and common practices like OAuth2, OpenID Connect, JWT Tokens, and MicroProfile JWT authentication in combination with the Payara Platform.

MicroProfile in Practice – Expose and visualise metrics, Configure your app & Secure REST endpoints.

In this datasheet learn about the tools provided by the Payara Platform to secure and restrict access to a production system, encrypt communication, and audit security events and configuration changes.

MicroProfile in Practice – Expose and visualise metrics, Configure your app & Secure REST endpoints.

This user guide written in collaboration with Snyk, takes you through 7 key pointers for developing applications with a minimal security risk. It will help you take responsibility for the security of your software, to best avoid becoming one of the 20,000 websites every day that get hacked on average.