CVE-2015-5176

Red Hat JBoss Portal 6.2.0 - Info Disclosure

Title source: llm
STIX 2.1

Description

The PortletRequestDispatcher in PortletBridge, as used in Red Hat JBoss Portal 6.2.0, does not properly enforce the security constraints of servlets, which allows remote attackers to gain access to resources via a request that asks to render a non-JSF resource.

References (1)

Core 1
Core References
Vendor Advisory vendor-advisory x_refsource_redhat
http://rhn.redhat.com/errata/RHSA-2015-1543.html

Scores

EPSS 0.0165
EPSS Percentile 74.0%

Details

CWE
CWE-17
Status published
Products (1)
redhat/jboss_portal 6.2.0
Published Aug 11, 2015
Tracked Since Feb 18, 2026