VDB

RHSA-2015:2541

RHSA-2015:2541 PUBLISHED CVSS 4 MEDIUM

It was found that JBoss EAP did not properly authorize a user performing a shut down. A remote user with the Monitor, Deployer, or Auditor role could use this flaw to shut down the EAP server, which is an action restricted to admin users.

Risk Scores

CVSS 2.0
4

Affected Products

VendorProductVersions
Red HatRed Hat JBoss Enterprise Application Platform 6.4

Timeline

  • Dec 2, 2015 CVE Published
  • Apr 30, 2026 Distribution Patch
  • Apr 30, 2026 Security Advisory
  • May 14, 2026 CVE Updated
  • May 15, 2026 Distribution Patch
  • May 15, 2026 Security Advisory
  • May 15, 2026 Security Advisory
Open in Interactive Console →
$ Console Community · 100/wk Open console ›