5.8
CVSSv2

CVE-2015-5176

Published: 11/08/2015 Updated: 11/08/2015
CVSS v2 Base Score: 5.8 | Impact Score: 4.9 | Exploitability Score: 8.6
VMScore: 516
Vector: AV:N/AC:M/Au:N/C:P/I:P/A:N

Vulnerability Summary

The PortletRequestDispatcher in PortletBridge, as used in Red Hat JBoss Portal 6.2.0, does not properly enforce the security constraints of servlets, which allows remote malicious users to gain access to resources via a request that asks to render a non-JSF resource.

Vulnerable Product Search on Vulmon Subscribe to Product

redhat jboss portal 6.2.0

Vendor Advisories

It was found that PortletBridge PortletRequestDispatcher did not respect security constraints set by the servlet if a portlet request asked for rendering of a non-JSF resource such as JSP or HTML A remote attacker could use this flaw to potentially bypass certain security constraints and gain access to restricted resources ...