Open redirect vulnerability in Red Hat JBoss Enterprise Portal Platform before 5.2.0 allows remote attackers to redirect users to arbitrary web sites and conduct phishing attacks via a URL in the initialURI parameter.
| Software | From | Fixed in |
|---|---|---|
| redhat / jboss_enterprise_portal_platform | 4.3.0-cp03 | 4.3.0-cp03.x |
| redhat / jboss_enterprise_portal_platform | 5.0.0 | 5.0.0.x |
| redhat / jboss_enterprise_portal_platform | 5.1.0 | 5.1.0.x |
| redhat / jboss_enterprise_portal_platform | 4.3.0-cp06 | 4.3.0-cp06.x |
| redhat / jboss_enterprise_portal_platform | 4.3.0-cp07 | 4.3.0-cp07.x |
| redhat / jboss_enterprise_portal_platform | 4.3.0 | 4.3.0.x |
| redhat / jboss_enterprise_portal_platform | - | 5.1.1.x |
| redhat / jboss_enterprise_portal_platform | 4.3.0-cp05 | 4.3.0-cp05.x |
| redhat / jboss_enterprise_portal_platform | 5.0.1 | 5.0.1.x |
| redhat / jboss_enterprise_portal_platform | 4.3.0-cp04 | 4.3.0-cp04.x |