CVE Vulnerabilities

CVE-2015-5176

Published: Aug 11, 2015 | Modified: Apr 12, 2025
CVSS 3.x
N/A
Source:
NVD
CVSS 2.x
5.8 MEDIUM
AV:N/AC:M/Au:N/C:P/I:P/A:N
RedHat/V2
4.9 MODERATE
AV:N/AC:M/Au:S/C:P/I:P/A:N
RedHat/V3
Ubuntu
root.io logo minimus.io logo echo.ai logo

The PortletRequestDispatcher in PortletBridge, as used in Red Hat JBoss Portal 6.2.0, does not properly enforce the security constraints of servlets, which allows remote attackers to gain access to resources via a request that asks to render a non-JSF resource.

Affected Software

NameVendorStart VersionEnd Version
Jboss_portalRedhat6.2.0 (including)6.2.0 (including)
Red Hat JBoss Portal 6.2RedHatportlet*

References