7.5
CVSSv2

CVE-2013-0314

Published: 12/04/2013 Updated: 15/04/2013
CVSS v2 Base Score: 7.5 | Impact Score: 6.4 | Exploitability Score: 10
VMScore: 668
Vector: AV:N/AC:L/Au:N/C:P/I:P/A:P

Vulnerability Summary

The GateIn Portal export/import gadget in JBoss Enterprise Portal Platform 5.2.2 does not properly check authentication when importing Zip files, which allows remote malicious users to modify site contents, remove the site, or alter the access controls for portlets.

Vulnerable Product Search on Vulmon Subscribe to Product

redhat jboss enterprise portal platform 5.2.2

Vendor Advisories

Synopsis Important: JBoss Enterprise Portal Platform 522 security update Type/Severity Security Advisory: Important Topic An update for the GateIn Portal component in JBoss Enterprise PortalPlatform 522 that fixes two security issues is now available from theRed Hat Customer PortalThe Red Hat Security ...