Lucene search

K
redhatRedHatRHSA-2015:1226
HistoryJul 14, 2015 - 4:32 p.m.

(RHSA-2015:1226) Moderate: Red Hat JBoss Portal 6.2.0 security update

2015-07-1416:32:13
access.redhat.com
9

0.002 Low

EPSS

Percentile

55.8%

Red Hat JBoss Portal is the open source implementation of the Java EE suite
of services and Portal services running atop Red Hat JBoss Enterprise
Application Platform.

It was found that JavaServer Faces PortletBridge-based portlets using
GenericPortlet’s default resource serving did not restrict access to
resources within the web application. An attacker could set the resource ID
field of a URL to potentially bypass security constraints and gain access
to restricted resources. (CVE-2015-3244)

Red Hat would like to thank Liferay, Inc. for reporting this issue.

All users of Red Hat JBoss Portal 6.2.0 as provided from the Red Hat
Customer Portal are advised to apply this update.

0.002 Low

EPSS

Percentile

55.8%

Related for RHSA-2015:1226