Lucene search

K
nvd[email protected]NVD:CVE-2015-3244
HistoryJul 16, 2015 - 11:00 a.m.

CVE-2015-3244

2015-07-1611:00:23
CWE-264
web.nvd.nist.gov

4.9 Medium

CVSS2

Attack Vector

NETWORK

Attack Complexity

MEDIUM

Authentication

SINGLE

Confidentiality Impact

PARTIAL

Integrity Impact

PARTIAL

Availability Impact

NONE

AV:N/AC:M/Au:S/C:P/I:P/A:N

6.1 Medium

AI Score

Confidence

Low

0.002 Low

EPSS

Percentile

55.8%

The Portlet Bridge for JavaServer Faces in Red Hat JBoss Portal 6.2.0, when used in portlets with the default resource serving for GenericPortlet, does not properly restrict access to restricted resources, which allows remote attackers to obtain sensitive information via a URL with a modified resource ID.

Affected configurations

NVD
Node
redhatjboss_enterprise_portal_platformMatch6.2.0

4.9 Medium

CVSS2

Attack Vector

NETWORK

Attack Complexity

MEDIUM

Authentication

SINGLE

Confidentiality Impact

PARTIAL

Integrity Impact

PARTIAL

Availability Impact

NONE

AV:N/AC:M/Au:S/C:P/I:P/A:N

6.1 Medium

AI Score

Confidence

Low

0.002 Low

EPSS

Percentile

55.8%

Related for NVD:CVE-2015-3244