PT-2015-2598 · Red Hat · Wildfly+1

Martin Prpič

·

Publicado

2015-10-27

·

Atualizado

2023-02-12

·

CVE-2015-5178

CVSS v2.0

4.3

Média

VetorAV:N/AC:M/Au:N/C:N/I:P/A:N
Name of the Vulnerable Software and Affected Versions Red Hat Enterprise Application Platform versions prior to 6.4.4 WildFly (formerly JBoss Application Server) versions prior to 6.4.4
Description The issue is related to the Management Console in Red Hat Enterprise Application Platform and WildFly, which does not send an X-Frame-Options HTTP header. This makes it easier for remote attackers to conduct clickjacking attacks via a crafted web page that contains a FRAME or IFRAME element. The vulnerability is associated with errors in security settings, allowing a remote attacker to exploit it and conduct clickjacking attacks using a specially formed page.
Recommendations For Red Hat Enterprise Application Platform versions prior to 6.4.4, update to version 6.4.4 or later. For WildFly (formerly JBoss Application Server) versions prior to 6.4.4, update to version 6.4.4 or later. As a temporary workaround, consider configuring the Management Console to send an X-Frame-Options HTTP header to prevent clickjacking attacks.

Correção

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

BDU:2015-11963
CVE-2015-5178
RHSA-2015:1904
RHSA-2015:1905
RHSA-2015:1906
RHSA-2015:1907

Produtos afetados

Red Hat Jboss Enterprise Application Platform
Wildfly