VulnerabilityModified
CVE-2015-5176
The PortletRequestDispatcher in PortletBridge, as used in Red Hat JBoss Portal 6.2.0, does not properly enforce the security constraints of servlets, which allows remote attackers to gain access to resources via a request that asks to render a non-JSF…
MEDIUM 5.8EPSS 1.65%
Does this matter?
Lower severity and a low EPSS score (1.65%). Track it; it rarely justifies an emergency change on its own.
Description
The PortletRequestDispatcher in PortletBridge, as used in Red Hat JBoss Portal 6.2.0, does not properly enforce the security constraints of servlets, which allows remote attackers to gain access to resources via a request that asks to render a non-JSF resource.
- CVSS 2.0
- 5.8 MEDIUMAV:N/AC:M/Au:N/C:P/I:P/A:N
- EPSS
- 1.65% probability · 75th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-17
- Affected
- redhat/jboss portal
- Source
- secalert@redhat.com
References
- http://rhn.redhat.com/errata/RHSA-2015-1543.htmlVendor Advisory
- http://rhn.redhat.com/errata/RHSA-2015-1543.htmlVendor Advisory
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.