The PortletRequestDispatcher in PortletBridge, as used in Red Hat JBoss Portal 6.2.0, does not properly enforce the security constraints of servlets, which allows remote attackers to gain access to resources via a request that asks to render a non-JSF resource.
References
Link Resource
http://rhn.redhat.com/errata/RHSA-2015-1543.html Vendor Advisory
History

No history.

cve-icon MITRE Information

Status: PUBLISHED

Assigner: redhat

Published: 2015-08-11T14:00:00

Updated: 2015-08-11T13:57:04

Reserved: 2015-07-01T00:00:00


Link: CVE-2015-5176

JSON object: View

cve-icon NVD Information

Status : Analyzed

Published: 2015-08-11T14:59:11.557

Modified: 2015-08-11T18:08:43.107


Link: CVE-2015-5176

JSON object: View

cve-icon Redhat Information

No data.

CWE