CVE-2015-5176: Red Hat JBoss Portal

Medium severity, CVSS 5.8. EPSS: 1.6% chance of exploitation in the next 30 days.

The PortletRequestDispatcher in PortletBridge, as used in Red Hat JBoss Portal 6.2.0, does not properly enforce the security constraints of servlets, which allows remote attackers to gain access to resources via a request that asks to render a non-JSF resource.

Affected products

  • Red Hat JBoss Portal: version 6.2.0 only

Published 2015-08-11. Last modified 2026-06-17.