4.3
CVSSv2

CVE-2015-5178

Published: 27/10/2015 Updated: 12/02/2023
CVSS v2 Base Score: 4.3 | Impact Score: 2.9 | Exploitability Score: 8.6
VMScore: 384
Vector: AV:N/AC:M/Au:N/C:N/I:P/A:N

Vulnerability Summary

The Management Console in Red Hat Enterprise Application Platform prior to 6.4.4 and WildFly (formerly JBoss Application Server) does not send an X-Frame-Options HTTP header, which makes it easier for remote malicious users to conduct clickjacking attacks via a crafted web page that contains a (1) FRAME or (2) IFRAME element.

Vulnerable Product Search on Vulmon Subscribe to Product

redhat jboss wildfly application server

redhat jboss enterprise application platform

Vendor Advisories

It was discovered that the EAP Management Console could be opened in an IFRAME, which made it possible to intercept and manipulate requests An attacker could use this flaw to trick a user into performing arbitrary actions in the Console (clickjacking) ...