A flaw was found in EAP's IIOP. The listener's NameService would accept bind operations without authentication, allowing an attacker to hijack JNDI lookups and binding them to a malicious ORB, achieving MITM or DoS on further invocations.
References
Configurations
No configuration.
History
No history.
Information
Published : 2026-08-11 09:17
Updated : 2026-09-04 09:17
NVD link : CVE-2026-15563
Mitre link : CVE-2026-15563
CVE.ORG link : CVE-2026-15563
JSON object : View
Products Affected
No product.
CWE
CWE-306
Missing Authentication for Critical Function
