CVE-2015-3244
published 2015-07-16CVE-2015-3244: The Portlet Bridge for JavaServer Faces in Red Hat JBoss Portal 6.2.0, when used in portlets with the default resource serving for GenericPortlet, does not…
PriorityP422medium4.9CVSS 2.0
AVNACMAuSCPIPAN
EPSS
1.50%
71.3th percentile
The Portlet Bridge for JavaServer Faces in Red Hat JBoss Portal 6.2.0, when used in portlets with the default resource serving for GenericPortlet, does not properly restrict access to restricted resources, which allows remote attackers to obtain sensitive information via a URL with a modified resource ID.
Affected
1 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| redhat | jboss_enterprise_portal_platform | — | — |
CVSS provenance
nvdv2.04.9MEDIUMAV:N/AC:M/Au:S/C:P/I:P/A:N
vendor_redhat4.9MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-3c2g-fm84-g225: The Portlet Bridge for JavaServer Faces in Red Hat JBoss Portal 6
ghsa_unreviewed·2022-05-17
CVE-2015-3244 [MEDIUM] GHSA-3c2g-fm84-g225: The Portlet Bridge for JavaServer Faces in Red Hat JBoss Portal 6
The Portlet Bridge for JavaServer Faces in Red Hat JBoss Portal 6.2.0, when used in portlets with the default resource serving for GenericPortlet, does not properly restrict access to restricted resources, which allows remote attackers to obtain sensitive information via a URL with a modified resource ID.
Red Hat
JSF: Information disclosure due to missing access restriction in portlet resource dispatching
vendor_redhat·2015-07-14·CVSS 4.9
CVE-2015-3244 [MEDIUM] CWE-862 JSF: Information disclosure due to missing access restriction in portlet resource dispatching
JSF: Information disclosure due to missing access restriction in portlet resource dispatching
The Portlet Bridge for JavaServer Faces in Red Hat JBoss Portal 6.2.0, when used in portlets with the default resource serving for GenericPortlet, does not properly restrict access to restricted resources, which allows remote attackers to obtain sensitive information via a URL with a modified resource ID.
It was found that JavaServer Faces PortletBridge-based portlets using GenericPortlet's default resource serving did not restrict access to resources within the web application. An attacker could set the resource ID field of a URL to potentially bypass security constraints and gain access to restricted resources.
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2015-3244 JSF: Information disclosure due to missing access restriction in portlet resource dispatching
bugzilla·2015-06-17·CVSS 4.9
CVE-2015-3244 [MEDIUM] CVE-2015-3244 JSF: Information disclosure due to missing access restriction in portlet resource dispatching
CVE-2015-3244 JSF: Information disclosure due to missing access restriction in portlet resource dispatching
It was found that JavaServer Faces PortletBridge-based portlets using GenericPortlet's default resource serving did not restrict access to resources within the web application. An attacker could set the resource ID field of a URL to potentially bypass security constraints and gain access to restricted resources.
Discussion:
Acknowledgements:
Red Hat would like to thank Liferay, Inc. for reporting this issue.
---
This issue has been addressed in the following products:
JBoss Portal 6.2.0
Via RHSA-2015:1226 https://rhn.redhat.com/errata/RHSA-2015-1226.html
Bugzilla
CVE-2015-3011 CVE-2015-3012 CVE-2015-3013 owncloud: various flaws fixed in 7.0.5
bugzilla·2015-05-04·CVSS 3.5
CVE-2015-3011 [LOW] CVE-2015-3011 CVE-2015-3012 CVE-2015-3013 owncloud: various flaws fixed in 7.0.5
CVE-2015-3011 CVE-2015-3012 CVE-2015-3013 owncloud: various flaws fixed in 7.0.5
The following flaws were fixed in the 7.0.5 release of ownCloud:
CVE-2015-3013 -- Bypass of file blacklist (oC-SA-2015-004)
https://owncloud.org/security/advisory/?id=oc-sa-2015-004
CVE-2015-3012 -- Multiple stored XSS in "documents" application (oC-SA-2015-002)
https://owncloud.org/security/advisory/?id=oc-sa-2015-002
CVE-2015-3011 -- Multiple stored XSS in "contacts" application (oC-SA-2015-001)
https://owncloud.org/security/advisory/?id=oc-sa-2015-001
Additional information:
https://www.debian.org/security/2015/dsa-3244
Discussion:
Created owncloud tracking bugs for this issue:
Affects: fedora-all [bug 1218245]
Affects: epel-6 [bug 1218246]
Affects: epel-7 [bug 1218247]
---
7.0.5 is already out f
http://rhn.redhat.com/errata/RHSA-2015-1226.htmlhttp://www.oracle.com/technetwork/topics/security/cpujul2015-2367936.htmlhttp://www.securityfocus.com/bid/75941https://bugzilla.redhat.com/show_bug.cgi?id=1232908http://rhn.redhat.com/errata/RHSA-2015-1226.htmlhttp://www.oracle.com/technetwork/topics/security/cpujul2015-2367936.htmlhttp://www.securityfocus.com/bid/75941https://bugzilla.redhat.com/show_bug.cgi?id=1232908
2015-07-16
Published