CVE-2013-0314
The GateIn Portal export/import gadget in JBoss Enterprise Portal Platform 5.2.2 does not properly check authentication when importing Zip files, which allows remote attackers to modify site contents, remove the site, or alter the access controls for…
Does this matter?
High impact if exploited, but EPSS currently rates exploitation as unlikely (1.64%). Schedule it in the normal patch cycle and watch for a rise in EPSS or a public exploit.
Description
The GateIn Portal export/import gadget in JBoss Enterprise Portal Platform 5.2.2 does not properly check authentication when importing Zip files, which allows remote attackers to modify site contents, remove the site, or alter the access controls for portlets.
- CVSS 2.0
- 7.5 HIGHAV:N/AC:L/Au:N/C:P/I:P/A:P
- EPSS
- 1.64% probability · 75th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-287
- Affected
- redhat/jboss enterprise portal platform
- Source
- secalert@redhat.com
References
- http://rhn.redhat.com/errata/RHSA-2013-0613.htmlVendor Advisory
- http://secunia.com/advisories/52552Vendor Advisory
- http://www.osvdb.org/91120
- https://bugzilla.redhat.com/show_bug.cgi?id=913327
- http://rhn.redhat.com/errata/RHSA-2013-0613.htmlVendor Advisory
- http://secunia.com/advisories/52552Vendor Advisory
- http://www.osvdb.org/91120
- https://bugzilla.redhat.com/show_bug.cgi?id=913327
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.