Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2026-15560

Опубликовано: 11 авг. 2026
Источник: redhat
CVSS3: 8.1
EPSS Низкий

Описание

when EAP runs with -secmgr, the openjdk-orb's JDKBridge honours attacker-supplied CDR codebase URLs during object unmarshalling on :3528, allowing an unauthenticated attacker to load and instantiate arbitrary classes from a remote URL in the server JVM before EJB security interceptors run.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat JBoss Enterprise Application Platform 8openjdk-orbAffected
Red Hat JBoss Enterprise Application Platform Expansion Packopenjdk-orbNot affected
Red Hat JBoss Enterprise Application Platform 7.4.25openjdk-orbFixedRHSA-2026:5380611.08.2026
Red Hat JBoss Enterprise Application Platform 7.4 ELS on RHEL 7eap7-activemq-artemisFixedRHSA-2026:5364411.08.2026
Red Hat JBoss Enterprise Application Platform 7.4 ELS on RHEL 7eap7-glassfish-jsfFixedRHSA-2026:5364411.08.2026
Red Hat JBoss Enterprise Application Platform 7.4 ELS on RHEL 7eap7-ironjacamarFixedRHSA-2026:5364411.08.2026
Red Hat JBoss Enterprise Application Platform 7.4 ELS on RHEL 7eap7-jackson-annotationsFixedRHSA-2026:5364411.08.2026
Red Hat JBoss Enterprise Application Platform 7.4 ELS on RHEL 7eap7-jackson-coreFixedRHSA-2026:5364411.08.2026
Red Hat JBoss Enterprise Application Platform 7.4 ELS on RHEL 7eap7-jackson-databindFixedRHSA-2026:5364411.08.2026
Red Hat JBoss Enterprise Application Platform 7.4 ELS on RHEL 7eap7-jackson-jaxrs-providersFixedRHSA-2026:5364411.08.2026

Показывать по

Дополнительная информация

Статус:

Important
Дефект:
CWE-829
https://bugzilla.redhat.com/show_bug.cgi?id=2483131openjdk-orb: unauthed class loading via IIOP in EAP

EPSS

Процентиль: 37%
0.00439
Низкий

8.1 High

CVSS3

Связанные уязвимости

CVSS3: 8.1
nvd
7 дней назад

when EAP runs with -secmgr, the openjdk-orb's JDKBridge honours attacker-supplied CDR codebase URLs during object unmarshalling on :3528, allowing an unauthenticated attacker to load and instantiate arbitrary classes from a remote URL in the server JVM before EJB security interceptors run.

CVSS3: 8.1
github
7 дней назад

when EAP runs with -secmgr, the openjdk-orb's JDKBridge honours attacker-supplied CDR codebase URLs during object unmarshalling on :3528, allowing an unauthenticated attacker to load and instantiate arbitrary classes from a remote URL in the server JVM before EJB security interceptors run.

EPSS

Процентиль: 37%
0.00439
Низкий

8.1 High

CVSS3