Attack Vector in EAP's IIOP Listener for Java Applications by Red Hat
CVE-2026-15563
Key Information:
What is CVE-2026-15563?
A vulnerability exists in the IIOP listener of Red Hat's Enterprise Application Platform (EAP) that permits unauthorized bind operations. Through this flaw, an attacker can manipulate JNDI lookups, redirecting them to a compromised Object Request Broker (ORB). This manipulation could facilitate man-in-the-middle (MITM) attacks or denial of service (DoS) scenarios on subsequent invocations, compromising the integrity and availability of applications relying on EAP.
Affected Version(s)
Red Hat JBoss Enterprise Application Platform 7.4 ELS on RHEL 7 0:2.16.0-22.redhat_00057.1.el7eap
Red Hat JBoss Enterprise Application Platform 7.4 ELS on RHEL 7 0:2.3.14-11.SP11_redhat_00001.1.el7eap
Red Hat JBoss Enterprise Application Platform 7.4 ELS on RHEL 7 0:1.5.26-2.Final_redhat_00001.1.el7eap