Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2026-15563

Опубликовано: 11 авг. 2026
Источник: redhat
CVSS3: 7.4
EPSS Низкий

Описание

A flaw was found in EAP's IIOP. The listener's NameService would accept bind operations without authentication, allowing an attacker to hijack JNDI lookups and binding them to a malicious ORB, achieving MITM or DoS on further invocations.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat JBoss Enterprise Application Platform 8wildfly-iiop-openjdkAffected
Red Hat JBoss Enterprise Application Platform Expansion Packwildfly-iiop-openjdkNot affected
Red Hat JBoss Enterprise Application Platform 7.4.25wildfly-iiop-openjdkFixedRHSA-2026:5380611.08.2026
Red Hat JBoss Enterprise Application Platform 7.4 ELS on RHEL 7eap7-activemq-artemisFixedRHSA-2026:5364411.08.2026
Red Hat JBoss Enterprise Application Platform 7.4 ELS on RHEL 7eap7-glassfish-jsfFixedRHSA-2026:5364411.08.2026
Red Hat JBoss Enterprise Application Platform 7.4 ELS on RHEL 7eap7-ironjacamarFixedRHSA-2026:5364411.08.2026
Red Hat JBoss Enterprise Application Platform 7.4 ELS on RHEL 7eap7-jackson-annotationsFixedRHSA-2026:5364411.08.2026
Red Hat JBoss Enterprise Application Platform 7.4 ELS on RHEL 7eap7-jackson-coreFixedRHSA-2026:5364411.08.2026
Red Hat JBoss Enterprise Application Platform 7.4 ELS on RHEL 7eap7-jackson-databindFixedRHSA-2026:5364411.08.2026
Red Hat JBoss Enterprise Application Platform 7.4 ELS on RHEL 7eap7-jackson-jaxrs-providersFixedRHSA-2026:5364411.08.2026

Показывать по

Дополнительная информация

Статус:

Important
Дефект:
CWE-306
https://bugzilla.redhat.com/show_bug.cgi?id=2483138wildfly-iiop-openjdk: Missing authentication on EAP's IIOP NameService leads to MITM or DoS

EPSS

Процентиль: 22%
0.0029
Низкий

7.4 High

CVSS3

Связанные уязвимости

CVSS3: 7.4
nvd
7 дней назад

A flaw was found in EAP's IIOP. The listener's NameService would accept bind operations without authentication, allowing an attacker to hijack JNDI lookups and binding them to a malicious ORB, achieving MITM or DoS on further invocations.

CVSS3: 7.4
github
7 дней назад

A flaw was found in EAP's IIOP. The listener's NameService would accept bind operations without authentication, allowing an attacker to hijack JNDI lookups and binding them to a malicious ORB, achieving MITM or DoS on further invocations.

EPSS

Процентиль: 22%
0.0029
Низкий

7.4 High

CVSS3