Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
No advisories yet.
Tue, 11 Aug 2026 14:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Redhat jboss Enterprise Application Platform Expansion Pack
|
|
| Vendors & Products |
Redhat jboss Enterprise Application Platform Expansion Pack
|
Tue, 11 Aug 2026 12:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| References |
| |
| Metrics |
threat_severity
|
threat_severity
|
Tue, 11 Aug 2026 09:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | when EAP runs with -secmgr, the openjdk-orb's JDKBridge honours attacker-supplied CDR codebase URLs during object unmarshalling on :3528, allowing an unauthenticated attacker to load and instantiate arbitrary classes from a remote URL in the server JVM before EJB security interceptors run. | |
| Title | Openjdk-orb: unauthed class loading via iiop in eap | |
| First Time appeared |
Redhat
Redhat jboss Enterprise Application Platform Redhat jbosseapxp |
|
| Weaknesses | CWE-829 | |
| CPEs | cpe:/a:redhat:jboss_enterprise_application_platform:7 cpe:/a:redhat:jboss_enterprise_application_platform:8 cpe:/a:redhat:jbosseapxp |
|
| Vendors & Products |
Redhat
Redhat jboss Enterprise Application Platform Redhat jbosseapxp |
|
| References |
| |
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: redhat
Published:
Updated: 2026-08-11T08:49:45.288Z
Reserved: 2026-07-13T05:05:58.334Z
Link: CVE-2026-15560
No data.
Status : Received
Published: 2026-08-11T09:17:12.823
Modified: 2026-08-11T09:17:12.823
Link: CVE-2026-15560
OpenCVE Enrichment
Updated: 2026-08-11T13:45:04Z
-
CWE-829
Inclusion of Functionality from Untrusted Control Sphere