Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2016-5422

Опубликовано: 31 авг. 2016
Источник: redhat
CVSS3: 9.9
CVSS2: 6.5

Описание

The web console in Red Hat JBoss Operations Network (JON) before 3.3.7 does not properly authorize requests to add users with the super user role, which allows remote authenticated users to gain admin privileges via a crafted POST request.

It was found that JBoss Operations Network allowed regular users to add a new super user by sending a specially crafted request to the web console. This attacks allows escalation of privileges.

Дополнительная информация

Статус:

Moderate
Дефект:
CWE-285
https://bugzilla.redhat.com/show_bug.cgi?id=1361933JON3: privilege escalation via improper authorization

9.9 Critical

CVSS3

6.5 Medium

CVSS2

Связанные уязвимости

CVSS3: 8.8
nvd
больше 9 лет назад

The web console in Red Hat JBoss Operations Network (JON) before 3.3.7 does not properly authorize requests to add users with the super user role, which allows remote authenticated users to gain admin privileges via a crafted POST request.

CVSS3: 8.8
github
больше 3 лет назад

The web console in Red Hat JBoss Operations Network (JON) before 3.3.7 does not properly authorize requests to add users with the super user role, which allows remote authenticated users to gain admin privileges via a crafted POST request.

9.9 Critical

CVSS3

6.5 Medium

CVSS2