CVE-2015-5176: Medium severity red hat jboss portal vulnerability
The PortletRequestDispatcher in PortletBridge, as used in Red Hat JBoss Portal 6.2.0, does not properly enforce the security constraints of servlets, which allows remote attackers to gain access to resources via a request that asks to render a non-JSF resource.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2015-5176?
CVE-2015-5176 has a medium severity rating due to its potential to allow unauthorized access to resources.
How do I fix CVE-2015-5176?
To mitigate CVE-2015-5176, update to a patched version of Red Hat JBoss Portal that addresses this vulnerability.
What type of vulnerability is CVE-2015-5176?
CVE-2015-5176 is a security vulnerability related to improper enforcement of servlet security constraints.
Who is affected by CVE-2015-5176?
CVE-2015-5176 affects users of Red Hat JBoss Portal version 6.2.0.
What impact does CVE-2015-5176 have on applications?
CVE-2015-5176 could allow remote attackers to access sensitive resources that should be protected.