VDB
RHSA-2015:2541
RHSA-2015:2541
PUBLISHED
CVSS 4 MEDIUM
It was found that JBoss EAP did not properly authorize a user performing a shut down. A remote user with the Monitor, Deployer, or Auditor role could use this flaw to shut down the EAP server, which is an action restricted to admin users.
Risk Scores
CVSS 2.0
4
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Red Hat | Red Hat JBoss Enterprise Application Platform 6.4 |
Timeline
- Dec 2, 2015 CVE Published
- Apr 30, 2026 Distribution Patch
- Apr 30, 2026 Security Advisory
- May 14, 2026 CVE Updated
- May 15, 2026 Distribution Patch
- May 15, 2026 Security Advisory
- May 15, 2026 Security Advisory
References
- https://access.redhat.com/errata/RHSA-2015:2541 advisory
- https://access.redhat.com/security/updates/classification/#critical advisory
- https://access.redhat.com/documentation/en-US/JBoss_Enterprise_Application_Platform/6.4/index.html advisory
- https://access.redhat.com/solutions/2045023 advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=1273046 issue
- https://bugzilla.redhat.com/show_bug.cgi?id=1275289 issue
- https://bugzilla.redhat.com/show_bug.cgi?id=1275301 issue
- https://bugzilla.redhat.com/show_bug.cgi?id=1275308 issue
- https://bugzilla.redhat.com/show_bug.cgi?id=1275317 issue
- https://bugzilla.redhat.com/show_bug.cgi?id=1275320 issue
- https://bugzilla.redhat.com/show_bug.cgi?id=1275684 issue
- https://bugzilla.redhat.com/show_bug.cgi?id=1275691 issue
- https://bugzilla.redhat.com/show_bug.cgi?id=1279594 issue
- https://access.redhat.com/security/cve/CVE-2015-5304 advisory
- https://www.cve.org/CVERecord?id=CVE-2015-7501 advisory
- http://foxglovesecurity.com/2015/11/06/what-do-weblogic-websphere-jboss-jenkins-opennms-and-your-application-have-in-common-this-vulnerability/ advisory
- https://access.redhat.com/jbossnetwork/restricted/listSoftware.html?product=appplatform&downloadType=securityPatches&version=6.4 advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=1275311 issue
- https://bugzilla.redhat.com/show_bug.cgi?id=1275314 issue
- https://bugzilla.redhat.com/show_bug.cgi?id=1275331 issue
…and 6 more