CVE-2015-5178
published 2015-10-27CVE-2015-5178: The Management Console in Red Hat Enterprise Application Platform before 6.4.4 and WildFly (formerly JBoss Application Server) does not send an X-Frame-Options…
PriorityP419medium4.3CVSS 2.0
AVNACMAuNCNIPAN
EPSS
1.71%
74.8th percentile
The Management Console in Red Hat Enterprise Application Platform before 6.4.4 and WildFly (formerly JBoss Application Server) does not send an X-Frame-Options HTTP header, which makes it easier for remote attackers to conduct clickjacking attacks via a crafted web page that contains a (1) FRAME or (2) IFRAME element.
Affected
2 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| redhat | jboss_enterprise_application_platform | <= 6.4.3 | — |
| redhat | jboss_wildfly_application_server | <= 2.0.0 | — |
CVSS provenance
nvdv2.04.3MEDIUMAV:N/AC:M/Au:N/C:N/I:P/A:N
vendor_redhat4.3MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-9x2p-wcwc-h875: The Management Console in Red Hat Enterprise Application Platform before 6
ghsa_unreviewed·2022-05-17
CVE-2015-5178 [MEDIUM] GHSA-9x2p-wcwc-h875: The Management Console in Red Hat Enterprise Application Platform before 6
The Management Console in Red Hat Enterprise Application Platform before 6.4.4 and WildFly (formerly JBoss Application Server) does not send an X-Frame-Options HTTP header, which makes it easier for remote attackers to conduct clickjacking attacks via a crafted web page that contains a (1) FRAME or (2) IFRAME element.
Red Hat
AS/WildFly: missing X-Frame-Options header leading to clickjacking
vendor_redhat·2015-10-15·CVSS 4.3
CVE-2015-5178 [MEDIUM] CWE-20 AS/WildFly: missing X-Frame-Options header leading to clickjacking
AS/WildFly: missing X-Frame-Options header leading to clickjacking
The Management Console in Red Hat Enterprise Application Platform before 6.4.4 and WildFly (formerly JBoss Application Server) does not send an X-Frame-Options HTTP header, which makes it easier for remote attackers to conduct clickjacking attacks via a crafted web page that contains a (1) FRAME or (2) IFRAME element.
It was discovered that the EAP Management Console could be opened in an IFRAME, which made it possible to intercept and manipulate requests. An attacker could use this flaw to trick a user into performing arbitrary actions in the Console (clickjacking).
No detection rules found.
No public exploits indexed.
http://rhn.redhat.com/errata/RHSA-2015-1904.htmlhttp://rhn.redhat.com/errata/RHSA-2015-1905.htmlhttp://rhn.redhat.com/errata/RHSA-2015-1906.htmlhttp://rhn.redhat.com/errata/RHSA-2015-1907.htmlhttp://rhn.redhat.com/errata/RHSA-2015-1908.htmlhttp://www.securitytracker.com/id/1033859https://bugzilla.redhat.com/show_bug.cgi?id=1250552http://rhn.redhat.com/errata/RHSA-2015-1904.htmlhttp://rhn.redhat.com/errata/RHSA-2015-1905.htmlhttp://rhn.redhat.com/errata/RHSA-2015-1906.htmlhttp://rhn.redhat.com/errata/RHSA-2015-1907.htmlhttp://rhn.redhat.com/errata/RHSA-2015-1908.htmlhttp://www.securitytracker.com/id/1033859https://bugzilla.redhat.com/show_bug.cgi?id=1250552
2015-10-27
Published