CVE-2015-5176
published 2015-08-11CVE-2015-5176: The PortletRequestDispatcher in PortletBridge, as used in Red Hat JBoss Portal 6.2.0, does not properly enforce the security constraints of servlets, which…
PriorityP434medium5.8CVSS 2.0
AVNACMAuNCPIPAN
EPSS
1.65%
73.8th percentile
The PortletRequestDispatcher in PortletBridge, as used in Red Hat JBoss Portal 6.2.0, does not properly enforce the security constraints of servlets, which allows remote attackers to gain access to resources via a request that asks to render a non-JSF resource.
Affected
1 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| redhat | jboss_portal | — | — |
CVSS provenance
nvdv2.05.8MEDIUMAV:N/AC:M/Au:N/C:P/I:P/A:N
vendor_redhat5.8MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Red Hat
PortletBridge: information disclosure via auto-dispatching of non-JSF resources
vendor_redhat·2015-08-04·CVSS 5.8
CVE-2015-5176 [MEDIUM] CWE-284 PortletBridge: information disclosure via auto-dispatching of non-JSF resources
PortletBridge: information disclosure via auto-dispatching of non-JSF resources
The PortletRequestDispatcher in PortletBridge, as used in Red Hat JBoss Portal 6.2.0, does not properly enforce the security constraints of servlets, which allows remote attackers to gain access to resources via a request that asks to render a non-JSF resource.
It was found that PortletBridge PortletRequestDispatcher did not respect security constraints set by the servlet if a portlet request asked for rendering of a non-JSF resource such as JSP or HTML. A remote attacker could use this flaw to potentially bypass certain security constraints and gain access to restricted resources.
GHSA
GHSA-66rg-hrjv-v265: The PortletRequestDispatcher in PortletBridge, as used in Red Hat JBoss Portal 6
ghsa_unreviewed·2022-05-17
CVE-2015-5176 [MEDIUM] GHSA-66rg-hrjv-v265: The PortletRequestDispatcher in PortletBridge, as used in Red Hat JBoss Portal 6
The PortletRequestDispatcher in PortletBridge, as used in Red Hat JBoss Portal 6.2.0, does not properly enforce the security constraints of servlets, which allows remote attackers to gain access to resources via a request that asks to render a non-JSF resource.
No detection rules found.
No public exploits indexed.
2015-08-11
Published