{"id":"CVE-2015-3158","aliases":[],"url":"https://o3.security/vulnerability/CVE-2015-3158","summary":"The invokeNextValve function in identity/federation/bindings/tomcat/idp/AbstractIDPValve.java in PicketLink before 2.8.0.Beta1 does not properly check role based authorization, which…","details":"The invokeNextValve function in identity/federation/bindings/tomcat/idp/AbstractIDPValve.java in PicketLink before 2.8.0.Beta1 does not properly check role based authorization, which allows remote authenticated users to gain access to restricted application resources via a (1) direct request or (2) request through an SP initiated flow.","published":"2015-08-26T19:59:01.690","modified":"2026-06-17T00:25:26.240","cvss":null,"epss":null,"cisaKev":null,"exploitsKnown":0,"affectedPackages":[],"fix":{"url":"https://github.com/picketlink/picketlink-bindings/pull/124","label":"picketlink/picketlink-bindings#124"},"references":[{"type":"WEB","url":"http://rhn.redhat.com/errata/RHSA-2015-1669.html"},{"type":"WEB","url":"http://rhn.redhat.com/errata/RHSA-2015-1670.html"},{"type":"WEB","url":"http://rhn.redhat.com/errata/RHSA-2015-1671.html"},{"type":"WEB","url":"http://rhn.redhat.com/errata/RHSA-2015-1672.html"},{"type":"WEB","url":"http://rhn.redhat.com/errata/RHSA-2015-1673.html"},{"type":"WEB","url":"https://bugzilla.redhat.com/show_bug.cgi?id=1216123"},{"type":"WEB","url":"https://github.com/picketlink/picketlink-bindings/pull/124"},{"type":"WEB","url":"https://issues.jboss.org/browse/PLINK-708"},{"type":"WEB","url":"http://rhn.redhat.com/errata/RHSA-2015-1669.html"},{"type":"WEB","url":"http://rhn.redhat.com/errata/RHSA-2015-1670.html"},{"type":"WEB","url":"http://rhn.redhat.com/errata/RHSA-2015-1671.html"},{"type":"WEB","url":"http://rhn.redhat.com/errata/RHSA-2015-1672.html"},{"type":"WEB","url":"http://rhn.redhat.com/errata/RHSA-2015-1673.html"},{"type":"WEB","url":"https://bugzilla.redhat.com/show_bug.cgi?id=1216123"},{"type":"WEB","url":"https://github.com/picketlink/picketlink-bindings/pull/124"},{"type":"WEB","url":"https://issues.jboss.org/browse/PLINK-708"}],"provenance":{"sources":["OSV.dev","NVD","FIRST.org (EPSS)"],"lastVerified":"2026-06-17T00:25:26.240"}}