Description
The PortletRequestDispatcher in PortletBridge, as used in Red Hat JBoss Portal 6.2.0, does not properly enforce the security constraints of servlets, which allows remote attackers to gain access to resources via a request that asks to render a non-JSF resource.
References (1)
Core 1
Core References
Vendor Advisory vendor-advisory
x_refsource_redhat
http://rhn.redhat.com/errata/RHSA-2015-1543.html
Scores
EPSS
0.0165
EPSS Percentile
74.0%
Details
CWE
CWE-17
Status
published
Products (1)
redhat/jboss_portal
6.2.0
Published
Aug 11, 2015
Tracked Since
Feb 18, 2026