REDHAT-BUG-2483138: High severity Red Hat JBoss EAP vulnerability
original reporting:
Missing Authentication — pre-auth CosNaming write ops on iiop-openjdk :3528 (JBoss EAP)
Missing authentication on the IIOP CosNaming service: the :3528 IIOP listener's NameService accepts bind/rebind/unbind operations without any authentication, allowing an unauthenticated attacker to hijack EJB JNDI lookups by rebinding stub references to an attacker-controlled ORB (MITM for all subsequent client invocations) or to unbind critical services for denial of service. findings/jboss-eap96.md
Affected Software
Event History
Frequently Asked Questions
What is the severity of REDHAT-BUG-2483138?
The severity of REDHAT-BUG-2483138 is high, rated at 7.
How do I fix REDHAT-BUG-2483138?
To fix REDHAT-BUG-2483138, ensure that authentication is implemented for the IIOP CosNaming service on JBoss EAP.
What is REDHAT-BUG-2483138 about?
REDHAT-BUG-2483138 describes a vulnerability where the IIOP CosNaming service allows unauthenticated bind/rebind/unbind operations.
Which software is affected by REDHAT-BUG-2483138?
The affected software for REDHAT-BUG-2483138 is Red Hat JBoss EAP.
When was REDHAT-BUG-2483138 published?
REDHAT-BUG-2483138 was published on May 29, 2026.