Описание
A flaw was found in EAP's IIOP. The listener's NameService would accept bind operations without authentication, allowing an attacker to hijack JNDI lookups and binding them to a malicious ORB, achieving MITM or DoS on further invocations.
Затронутые пакеты
| Платформа | Пакет | Состояние | Рекомендация | Релиз |
|---|---|---|---|---|
| Red Hat JBoss Enterprise Application Platform 8 | wildfly-iiop-openjdk | Affected | ||
| Red Hat JBoss Enterprise Application Platform Expansion Pack | wildfly-iiop-openjdk | Not affected | ||
| Red Hat JBoss Enterprise Application Platform 7.4.25 | wildfly-iiop-openjdk | Fixed | RHSA-2026:53806 | 11.08.2026 |
| Red Hat JBoss Enterprise Application Platform 7.4 ELS on RHEL 7 | eap7-activemq-artemis | Fixed | RHSA-2026:53644 | 11.08.2026 |
| Red Hat JBoss Enterprise Application Platform 7.4 ELS on RHEL 7 | eap7-glassfish-jsf | Fixed | RHSA-2026:53644 | 11.08.2026 |
| Red Hat JBoss Enterprise Application Platform 7.4 ELS on RHEL 7 | eap7-ironjacamar | Fixed | RHSA-2026:53644 | 11.08.2026 |
| Red Hat JBoss Enterprise Application Platform 7.4 ELS on RHEL 7 | eap7-jackson-annotations | Fixed | RHSA-2026:53644 | 11.08.2026 |
| Red Hat JBoss Enterprise Application Platform 7.4 ELS on RHEL 7 | eap7-jackson-core | Fixed | RHSA-2026:53644 | 11.08.2026 |
| Red Hat JBoss Enterprise Application Platform 7.4 ELS on RHEL 7 | eap7-jackson-databind | Fixed | RHSA-2026:53644 | 11.08.2026 |
| Red Hat JBoss Enterprise Application Platform 7.4 ELS on RHEL 7 | eap7-jackson-jaxrs-providers | Fixed | RHSA-2026:53644 | 11.08.2026 |
Показывать по
Дополнительная информация
Статус:
EPSS
7.4 High
CVSS3
Связанные уязвимости
A flaw was found in EAP's IIOP. The listener's NameService would accept bind operations without authentication, allowing an attacker to hijack JNDI lookups and binding them to a malicious ORB, achieving MITM or DoS on further invocations.
A flaw was found in EAP's IIOP. The listener's NameService would accept bind operations without authentication, allowing an attacker to hijack JNDI lookups and binding them to a malicious ORB, achieving MITM or DoS on further invocations.
EPSS
7.4 High
CVSS3