cbcvebase.
CVE-2015-3244
published 2015-07-16

CVE-2015-3244: The Portlet Bridge for JavaServer Faces in Red Hat JBoss Portal 6.2.0, when used in portlets with the default resource serving for GenericPortlet, does not…

PriorityP422medium4.9CVSS 2.0
AVNACMAuSCPIPAN
EPSS
1.50%
71.3th percentile
The Portlet Bridge for JavaServer Faces in Red Hat JBoss Portal 6.2.0, when used in portlets with the default resource serving for GenericPortlet, does not properly restrict access to restricted resources, which allows remote attackers to obtain sensitive information via a URL with a modified resource ID.

Affected

1 ranges
VendorProductVersion rangeFixed in
redhatjboss_enterprise_portal_platform

CVSS provenance

nvdv2.04.9MEDIUMAV:N/AC:M/Au:S/C:P/I:P/A:N
vendor_redhat4.9MEDIUM
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.