Attack Vector in EAP's IIOP Listener for Java Applications by Red Hat
CVE-2026-15563

7.4HIGH

What is CVE-2026-15563?

A vulnerability exists in the IIOP listener of Red Hat's Enterprise Application Platform (EAP) that permits unauthorized bind operations. Through this flaw, an attacker can manipulate JNDI lookups, redirecting them to a compromised Object Request Broker (ORB). This manipulation could facilitate man-in-the-middle (MITM) attacks or denial of service (DoS) scenarios on subsequent invocations, compromising the integrity and availability of applications relying on EAP.

References

CVSS V3.1

Score:
7.4
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
High
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.