Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2016-5406

Опубликовано: 26 июл. 2016
Источник: redhat
CVSS3: 7.5
CVSS2: 7
EPSS Низкий

Описание

The domain controller in Red Hat JBoss Enterprise Application Platform (EAP) 7.x before 7.0.2 allows remote authenticated users to gain privileges by leveraging failure to propagate administrative RBAC configuration to all slaves.

The domain controller will not propagate its administrative RBAC configuration to some slaves. An attacker could use this to escalate their privileges.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat JBoss Enterprise Application Platform 7DomainManagementNot affected
Red Hat JBoss EAP 7FixedRHSA-2016:184108.09.2016
Red Hat JBoss EAP 7FixedRHSA-2017:345613.12.2017
Red Hat JBoss Enterprise Application Platform 7.0 for RHEL 6eap7-activemq-artemisFixedRHSA-2016:183808.09.2016
Red Hat JBoss Enterprise Application Platform 7.0 for RHEL 6eap7-apache-cxfFixedRHSA-2016:183808.09.2016
Red Hat JBoss Enterprise Application Platform 7.0 for RHEL 6eap7-jberetFixedRHSA-2016:183808.09.2016
Red Hat JBoss Enterprise Application Platform 7.0 for RHEL 6eap7-jboss-jstl-api_1.2_specFixedRHSA-2016:183808.09.2016
Red Hat JBoss Enterprise Application Platform 7.0 for RHEL 6eap7-jboss-security-negotiationFixedRHSA-2016:183808.09.2016
Red Hat JBoss Enterprise Application Platform 7.0 for RHEL 6eap7-jbossws-commonFixedRHSA-2016:183808.09.2016
Red Hat JBoss Enterprise Application Platform 7.0 for RHEL 6eap7-jbossws-cxfFixedRHSA-2016:183808.09.2016

Показывать по

Дополнительная информация

Статус:

Moderate
https://bugzilla.redhat.com/show_bug.cgi?id=1359014EAP7 Privilege escalation when managing domain including earlier version slaves

EPSS

Процентиль: 81%
0.01504
Низкий

7.5 High

CVSS3

7 High

CVSS2

Связанные уязвимости

CVSS3: 8.8
nvd
больше 9 лет назад

The domain controller in Red Hat JBoss Enterprise Application Platform (EAP) 7.x before 7.0.2 allows remote authenticated users to gain privileges by leveraging failure to propagate administrative RBAC configuration to all slaves.

CVSS3: 8.8
github
больше 3 лет назад

The domain controller in Red Hat JBoss Enterprise Application Platform (EAP) 7.x before 7.0.2 allows remote authenticated users to gain privileges by leveraging failure to propagate administrative RBAC configuration to all slaves.

EPSS

Процентиль: 81%
0.01504
Низкий

7.5 High

CVSS3

7 High

CVSS2

Уязвимость CVE-2016-5406