漏洞类别:Local
漏洞等级:
漏洞信息
Red Hat JBoss Portal is the open source implementation of the Java EE suite of services and Portal services running atop Red Hat JBoss Enterprise Application Platform.
It was found that PortletBridge PortletRequestDispatcher did not respect security constraints set by the servlet if a portlet request asked for rendering of a non-JSF resource such as JSP or HTML. A remote attacker could use this flaw to potentially bypass certain security constraints and gain access to restricted resources. (CVE-2015-5176)
漏洞危害
A remote attacker could use this flaw to potentially bypass certain security constraints and gain access to restricted resources.
解决方案
The vendor has released advisories to fix these vulnerabilities. Refer to the following link for further details: RHSA-2015:1543
Patch:
Following are links for downloading patches to fix the vulnerabilities:
0day
文章评论