AUGUST 4, 2026
Live Feed
Return to register
Case File

CVE-2015-5188

MEDIUM · CVSS 6.8 EPSS 1.14%

Source: NVD + CISA KEV + EPSS (historical backfill) · Published 2015-10-27 · Last synced 2026-08-04

Field Assessment

AI analysis pending.

CVE
CVE-2015-5188
Severity
MEDIUM
CVSS
6.8
EPSS
1.14%

Original Filing — NVD Description

Cross-site request forgery (CSRF) vulnerability in the Web Console (web-console) in Red Hat Enterprise Application Platform before 6.4.4 and WildFly (formerly JBoss Application Server) before 2.0.0.CR9 allows remote attackers to hijack the authentication of administrators for requests that make arbitrary changes to an instance via vectors involving a file upload using a multipart/form-data submission.