CVE-2015-5176

The PortletRequestDispatcher in PortletBridge, as used in Red Hat JBoss Portal 6.2.0, does not properly enforce the security constraints of servlets, which allows remote attackers to gain access to resources via a request that asks to render a non-JSF resource.
References
Link Resource
http://rhn.redhat.com/errata/RHSA-2015-1543.html Vendor Advisory
Advertisement

NeevaHost hosting service

Configurations

Configuration 1 (hide)

cpe:2.3:a:redhat:jboss_portal:6.2.0:*:*:*:*:*:*:*

Information

Published : 2015-08-11 07:59

Updated : 2015-08-11 11:08


NVD link : CVE-2015-5176

Mitre link : CVE-2015-5176


JSON object : View

CWE
CWE-17

DEPRECATED: Code

Advertisement

dedicated server usa

Products Affected

redhat

  • jboss_portal