4.9
CVSSv2

CVE-2015-3244

Published: 16/07/2015 Updated: 28/11/2016
CVSS v2 Base Score: 4.9 | Impact Score: 4.9 | Exploitability Score: 6.8
VMScore: 436
Vector: AV:N/AC:M/Au:S/C:P/I:P/A:N

Vulnerability Summary

The Portlet Bridge for JavaServer Faces in Red Hat JBoss Portal 6.2.0, when used in portlets with the default resource serving for GenericPortlet, does not properly restrict access to restricted resources, which allows remote malicious users to obtain sensitive information via a URL with a modified resource ID.

Vulnerable Product Search on Vulmon Subscribe to Product

redhat jboss enterprise portal platform 6.2.0

Vendor Advisories

It was found that JavaServer Faces PortletBridge-based portlets using GenericPortlet's default resource serving did not restrict access to resources within the web application An attacker could set the resource ID field of a URL to potentially bypass security constraints and gain access to restricted resources ...