CVE-2015-3158

Impact:
Moderate
Public Date:
2015-06-05
Bugzilla:
1216123: CVE-2015-3158 PicketLink: PicketLink IDP ignores role based authorization
A flaw was found in the PicketLink Identity Provider Configuration (IDP) where, under specific conditions, the IDP ignores role-based authorization. This could lead to an authenticated user being able to access application resources that are not permitted for a given role.

Find out more about CVE-2015-3158 from the MITRE CVE dictionary dictionary and NIST NVD.

CVSS v2 metrics

Base Score 3.5
Base Metrics AV:N/AC:M/Au:S/C:P/I:N/A:N
Access Vector Network
Access Complexity Medium
Authentication Single
Confidentiality Impact Partial
Integrity Impact None
Availability Impact None

Find out more about Red Hat support for the Common Vulnerability Scoring System (CVSS).

Red Hat Security Errata

Platform Errata Release Date
Red Hat JBoss Enterprise Application Platform 6 for RHEL 6 Server RHSA-2015:1670 2015-08-24
Red Hat JBoss Enterprise Application Platform 6 for RHEL 6 Server (jboss-ec2-eap) RHSA-2015:1673 2015-08-24
Red Hat JBoss Enterprise Application Platform 6.3 for RHEL 7 Server RHSA-2015:1671 2015-08-24
Red Hat JBoss Enterprise Application Platform 6.4 RHSA-2015:1672 2015-08-24
Red Hat JBoss Enterprise Application Platform 6 for RHEL 5 Server RHSA-2015:1669 2015-08-24

Affected Packages State

Platform Package State
Red Hat JBoss Portal Platform 6 picketlink Will not fix
Red Hat JBoss Operations Network 3 picketlink Will not fix
Red Hat JBoss Fuse Service Works 6 picketlink Will not fix
Red Hat JBoss Enterprise SOA Platform 5 picketlink Will not fix
Red Hat JBoss EAP 5 picketlink Will not fix
Red Hat JBoss Data Virtualization 6 picketlink Will not fix
Red Hat JBoss Data Grid 6 picketlink Will not fix
Red Hat JBoss BRMS 6 picketlink Will not fix
Red Hat JBoss BPMS 6 picketlink Will not fix

Last Modified
Close

Welcome! Check out the Getting Started with Red Hat page for quick tours and guides for common tasks.