Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2016-8656

Опубликовано: 15 сент. 2016
Источник: redhat
CVSS3: 7
CVSS2: 6.9
EPSS Низкий

Описание

Jboss jbossas before versions 5.2.0-23, 6.4.13, 7.0.5 is vulnerable to an unsafe file handling in the jboss init script which could result in local privilege escalation.

It was discovered that the jboss init script performed unsafe file handling which could result in local privilege escalation.

Отчет

It was found that a variant of the Tomcat CVE-2016-1240 exploit is also applicable to Red Hat JBoss Enterprise Application Platform 5, 6, and 7. CVE-2016-8656 addresses these problems with JBoss EAP. The issue is now corrected in the various versions of Red Hat JBoss Enterprise Application Platform including EAP 6.4.13 and EAP 7.0.5. For further information please refer to https://access.redhat.com/articles/3016681

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat JBoss Enterprise Application Platform 6jbossWill not fix
Red Hat JBoss Enterprise Application Platform 5 for RHEL 5jbossasFixedRHSA-2018:160917.05.2018
Red Hat JBoss Enterprise Application Platform 5 for RHEL 6jbossasFixedRHSA-2018:160917.05.2018
Red Hat JBoss Enterprise Application Platform 6.4 for RHEL 5apache-cxfFixedRHSA-2017:024602.02.2017
Red Hat JBoss Enterprise Application Platform 6.4 for RHEL 5hornetqFixedRHSA-2017:024602.02.2017
Red Hat JBoss Enterprise Application Platform 6.4 for RHEL 5infinispanFixedRHSA-2017:024602.02.2017
Red Hat JBoss Enterprise Application Platform 6.4 for RHEL 5jboss-as-appclientFixedRHSA-2017:024602.02.2017
Red Hat JBoss Enterprise Application Platform 6.4 for RHEL 5jbossas-appclientFixedRHSA-2017:024602.02.2017
Red Hat JBoss Enterprise Application Platform 6.4 for RHEL 5jbossas-bundlesFixedRHSA-2017:024602.02.2017
Red Hat JBoss Enterprise Application Platform 6.4 for RHEL 5jboss-as-cliFixedRHSA-2017:024602.02.2017

Показывать по

Дополнительная информация

Статус:

Important
Дефект:
CWE-284
https://bugzilla.redhat.com/show_bug.cgi?id=1400344jboss: jbossas: unsafe chown of server.log in jboss init script allows privilege escalation

EPSS

Процентиль: 22%
0.00071
Низкий

7 High

CVSS3

6.9 Medium

CVSS2

Связанные уязвимости

CVSS3: 7
nvd
больше 7 лет назад

Jboss jbossas before versions 5.2.0-23, 6.4.13, 7.0.5 is vulnerable to an unsafe file handling in the jboss init script which could result in local privilege escalation.

CVSS3: 7.8
github
больше 3 лет назад

Jboss jbossas before versions 5.2.0-23, 6.4.13, 7.0.5 is vulnerable to an unsafe file handling in the jboss init script which could result in local privilege escalation.

EPSS

Процентиль: 22%
0.00071
Низкий

7 High

CVSS3

6.9 Medium

CVSS2

Уязвимость CVE-2016-8656