Impact
Unvalidated bind operations in the IIOP NameService of Red Hat JBoss Enterprise Application Platform allow an unauthenticated attacker to register arbitrary objects. By hijacking JNDI lookups, the attacker can redirect service calls to a malicious ORB, which can lead to a man‑in‑the‑middle scenario or to a denial‑of‑service on subsequent invocations. The flaw is caused by a missing authentication check, which makes the system vulnerable to unauthorized access (CWE‑306).
Affected Systems
All supported releases of Red Hat JBoss Enterprise Application Platform that expose the IIOP NameService are affected, including versions 7, 8, and the Expansion Pack. None of the affected products include the authentication fix in their current versions.
Risk and Exploitability
The CVSS score of 7.4 reflects a high risk for confidentiality, integrity, and availability. EPSS data is not available, and the vulnerability is not listed in the CISA KEV catalog. The likely attack vector is remote network access to the IIOP listener, though the description does not explicitly state this; the flaw allows any host that can reach the listener to issue unauthenticated bind requests. This makes exploitation plausible in exposed environments, and an attacker could perform a full MITM attack or cause a denial of service by disrupting JNDI resolution.
OpenCVE Enrichment