REDHAT-BUG-2483138: High severity Red Hat JBoss EAP vulnerability
original reporting:
Missing Authentication — pre-auth CosNaming write ops on iiop-openjdk :3528 (JBoss EAP)
Missing authentication on the IIOP CosNaming service: the :3528 IIOP listener's NameService accepts bind/rebind/unbind operations without any authentication, allowing an unauthenticated attacker to hijack EJB JNDI lookups by rebinding stub references to an attacker-controlled ORB (MITM for all subsequent client invocations) or to unbind critical services for denial of service. findings/jboss-eap96.md