SOC status:Duty analyst on shift

UK Cyber Defence
VulnerabilityModified

CVE-2015-5176

The PortletRequestDispatcher in PortletBridge, as used in Red Hat JBoss Portal 6.2.0, does not properly enforce the security constraints of servlets, which allows remote attackers to gain access to resources via a request that asks to render a non-JSF…

MEDIUM 5.8EPSS 1.65%

Does this matter?

Lower severity and a low EPSS score (1.65%). Track it; it rarely justifies an emergency change on its own.

Description

The PortletRequestDispatcher in PortletBridge, as used in Red Hat JBoss Portal 6.2.0, does not properly enforce the security constraints of servlets, which allows remote attackers to gain access to resources via a request that asks to render a non-JSF resource.

CVSS 2.0
5.8 MEDIUMAV:N/AC:M/Au:N/C:P/I:P/A:N
EPSS
1.65% probability · 75th percentile
CISA KEV
Not listed
Weakness
CWE-17
Affected
redhat/jboss portal
Source
secalert@redhat.com

Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.