First published: Wed Jun 17 2015(Updated: )
It was found that JavaServer Faces PortletBridge-based portlets using GenericPortlet's default resource serving did not restrict access to resources within the web application. An attacker could set the resource ID field of a URL to potentially bypass security constraints and gain access to restricted resources.
Credit: secalert@redhat.com
Affected Software | Affected Version | How to fix |
---|---|---|
Red Hat JBoss Portal | =6.2.0 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2015-3244 is classified as a moderate severity vulnerability.
To fix CVE-2015-3244, update your JBoss Enterprise Portal Platform to version 6.2.1 or later.
CVE-2015-3244 allows an attacker to bypass security constraints and access restricted resources.
CVE-2015-3244 affects Red Hat JBoss Enterprise Portal Platform version 6.2.0.
Yes, CVE-2015-3244 can lead to unauthorized access, which means user authentication mechanisms may be bypassed.