Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2026-15560

Опубликовано: 11 авг. 2026
Источник: nvd
CVSS3: 8.1
EPSS Низкий

Описание

when EAP runs with -secmgr, the openjdk-orb's JDKBridge honours attacker-supplied CDR codebase URLs during object unmarshalling on :3528, allowing an unauthenticated attacker to load and instantiate arbitrary classes from a remote URL in the server JVM before EJB security interceptors run.

EPSS

Процентиль: 37%
0.00439
Низкий

8.1 High

CVSS3

Дефекты

CWE-829

Связанные уязвимости

CVSS3: 8.1
redhat
7 дней назад

when EAP runs with -secmgr, the openjdk-orb's JDKBridge honours attacker-supplied CDR codebase URLs during object unmarshalling on :3528, allowing an unauthenticated attacker to load and instantiate arbitrary classes from a remote URL in the server JVM before EJB security interceptors run.

CVSS3: 8.1
github
7 дней назад

when EAP runs with -secmgr, the openjdk-orb's JDKBridge honours attacker-supplied CDR codebase URLs during object unmarshalling on :3528, allowing an unauthenticated attacker to load and instantiate arbitrary classes from a remote URL in the server JVM before EJB security interceptors run.

EPSS

Процентиль: 37%
0.00439
Низкий

8.1 High

CVSS3

Дефекты

CWE-829