Red Hat Bugzilla – Bug 1248809
CVE-2015-5182 A-MQ Console: CSRF via form-based API call
Last modified: 2018-04-22 16:11:21 EDT
It was found that A-MQ's jolokia API does not have token or referrer checks, and could possibly allow a cross-site request forgery (CSRF) attack. An attacker could use this vulnerability to run application code with the same permissions as an authenticated user.
Acknowledgements: Red Hat would like to thank Naftali Rosenbaum of Comsec Consulting for reporting this issue.