CVE-2015-5178

The Management Console in Red Hat Enterprise Application Platform before 6.4.4 and WildFly (formerly JBoss Application Server) does not send an X-Frame-Options HTTP header, which makes it easier for remote attackers to conduct clickjacking attacks via a crafted web page that contains a (1) FRAME or (2) IFRAME element.
Configurations

Configuration 1 (hide)

cpe:2.3:a:redhat:jboss_wildfly_application_server:*:cr8:*:*:*:*:*:*

Configuration 2 (hide)

cpe:2.3:a:redhat:jboss_enterprise_application_platform:*:*:*:*:*:*:*:*

History

12 Feb 2023, 23:15

Type Values Removed Values Added
References
  • {'url': 'https://access.redhat.com/errata/RHSA-2015:1904', 'name': 'https://access.redhat.com/errata/RHSA-2015:1904', 'tags': [], 'refsource': 'MISC'}
  • {'url': 'https://access.redhat.com/security/cve/CVE-2015-5178', 'name': 'https://access.redhat.com/security/cve/CVE-2015-5178', 'tags': [], 'refsource': 'MISC'}
  • {'url': 'https://access.redhat.com/errata/RHSA-2015:1906', 'name': 'https://access.redhat.com/errata/RHSA-2015:1906', 'tags': [], 'refsource': 'MISC'}
  • {'url': 'https://access.redhat.com/errata/RHSA-2015:1905', 'name': 'https://access.redhat.com/errata/RHSA-2015:1905', 'tags': [], 'refsource': 'MISC'}
  • {'url': 'https://access.redhat.com/errata/RHSA-2015:1907', 'name': 'https://access.redhat.com/errata/RHSA-2015:1907', 'tags': [], 'refsource': 'MISC'}
Summary It was discovered that the EAP Management Console could be opened in an IFRAME, which made it possible to intercept and manipulate requests. An attacker could use this flaw to trick a user into performing arbitrary actions in the Console (clickjacking). The Management Console in Red Hat Enterprise Application Platform before 6.4.4 and WildFly (formerly JBoss Application Server) does not send an X-Frame-Options HTTP header, which makes it easier for remote attackers to conduct clickjacking attacks via a crafted web page that contains a (1) FRAME or (2) IFRAME element.

02 Feb 2023, 16:16

Type Values Removed Values Added
References
  • (MISC) https://access.redhat.com/errata/RHSA-2015:1904 -
  • (MISC) https://access.redhat.com/security/cve/CVE-2015-5178 -
  • (MISC) https://access.redhat.com/errata/RHSA-2015:1906 -
  • (MISC) https://access.redhat.com/errata/RHSA-2015:1905 -
  • (MISC) https://access.redhat.com/errata/RHSA-2015:1907 -
Summary The Management Console in Red Hat Enterprise Application Platform before 6.4.4 and WildFly (formerly JBoss Application Server) does not send an X-Frame-Options HTTP header, which makes it easier for remote attackers to conduct clickjacking attacks via a crafted web page that contains a (1) FRAME or (2) IFRAME element. It was discovered that the EAP Management Console could be opened in an IFRAME, which made it possible to intercept and manipulate requests. An attacker could use this flaw to trick a user into performing arbitrary actions in the Console (clickjacking).

Information

Published : 2015-10-27 16:59

Updated : 2023-12-10 11:46


NVD link : CVE-2015-5178

Mitre link : CVE-2015-5178

CVE.ORG link : CVE-2015-5178


JSON object : View

Products Affected

redhat

  • jboss_enterprise_application_platform
  • jboss_wildfly_application_server
CWE
CWE-254

7PK - Security Features