CVE Vulnerabilities

CVE-2015-5176

Published: Aug 11, 2015 | Modified: Aug 11, 2015
CVSS 3.x
N/A
Source:
NVD
CVSS 2.x
5.8 MEDIUM
AV:N/AC:M/Au:N/C:P/I:P/A:N
RedHat/V2
4.9 MODERATE
AV:N/AC:M/Au:S/C:P/I:P/A:N
RedHat/V3
Ubuntu

The PortletRequestDispatcher in PortletBridge, as used in Red Hat JBoss Portal 6.2.0, does not properly enforce the security constraints of servlets, which allows remote attackers to gain access to resources via a request that asks to render a non-JSF resource.

Affected Software

Name Vendor Start Version End Version
Jboss_portal Redhat 6.2.0 (including) 6.2.0 (including)
Red Hat JBoss Portal 6.2 RedHat portlet *

References