CVE-2015-5178
AS/WildFly: missing X-Frame-Options header leading to clickjacking
Severity Score
Exploit Likelihood
Affected Versions
Public Exploits
0Exploited in Wild
-Decision
Descriptions
The Management Console in Red Hat Enterprise Application Platform before 6.4.4 and WildFly (formerly JBoss Application Server) does not send an X-Frame-Options HTTP header, which makes it easier for remote attackers to conduct clickjacking attacks via a crafted web page that contains a (1) FRAME or (2) IFRAME element.
Management Console en Red Hat Enterprise Application Platform en versiones anteriores a 6.4.4 y WildFly (anteriormente JBoss Application Server) no envía una cabecera HTTP X-Frame-Options, lo que hace más fácil para atacantes remotos llevar a cabo ataques de secuestro de click a través de una página web manipulada que contiene un elemento (1) FRAME o (2) IFRAME.
It was discovered that the EAP Management Console could be opened in an IFRAME, which made it possible to intercept and manipulate requests. An attacker could use this flaw to trick a user into performing arbitrary actions in the Console (clickjacking).
CVSS Scores
SSVC
- Decision:-
Timeline
- 2015-07-01 CVE Reserved
- 2015-10-15 CVE Published
- 2023-03-08 EPSS Updated
- 2024-08-06 CVE Updated
- ---------- Exploited in Wild
- ---------- KEV Due Date
- ---------- First Exploit
CWE
- CWE-20: Improper Input Validation
- CWE-254: 7PK - Security Features
CAPEC
References (8)
URL | Tag | Source |
---|---|---|
http://www.securitytracker.com/id/1033859 | Vdb Entry |
URL | Date | SRC |
---|
URL | Date | SRC |
---|
URL | Date | SRC |
---|---|---|
http://rhn.redhat.com/errata/RHSA-2015-1904.html | 2023-02-12 | |
http://rhn.redhat.com/errata/RHSA-2015-1905.html | 2023-02-12 | |
http://rhn.redhat.com/errata/RHSA-2015-1906.html | 2023-02-12 | |
http://rhn.redhat.com/errata/RHSA-2015-1907.html | 2023-02-12 | |
http://rhn.redhat.com/errata/RHSA-2015-1908.html | 2023-02-12 | |
https://bugzilla.redhat.com/show_bug.cgi?id=1250552 | 2015-10-15 | |
https://access.redhat.com/security/cve/CVE-2015-5178 | 2015-10-15 |
Affected Vendors, Products, and Versions
Vendor | Product | Version | Other | Status | ||||||
---|---|---|---|---|---|---|---|---|---|---|
Vendor | Product | Version | Other | Status | <-- --> | Vendor | Product | Version | Other | Status |
Redhat Search vendor "Redhat" | Jboss Wildfly Application Server Search vendor "Redhat" for product "Jboss Wildfly Application Server" | <= 2.0.0 Search vendor "Redhat" for product "Jboss Wildfly Application Server" and version " <= 2.0.0" | cr8 |
Affected
| ||||||
Redhat Search vendor "Redhat" | Jboss Enterprise Application Platform Search vendor "Redhat" for product "Jboss Enterprise Application Platform" | <= 6.4.3 Search vendor "Redhat" for product "Jboss Enterprise Application Platform" and version " <= 6.4.3" | - |
Affected
|