First published: Fri Jul 22 2016(Updated: )
The domain controller in Red Hat JBoss Enterprise Application Platform (EAP) 7.x before 7.0.2 allows remote authenticated users to gain privileges by leveraging failure to propagate administrative RBAC configuration to all slaves.
Credit: secalert@redhat.com
Affected Software | Affected Version | How to fix |
---|---|---|
JBoss Enterprise Application Platform | <=7.0.1 | |
Red Hat Enterprise Linux | =6.0 | |
Red Hat Enterprise Linux | =7.0 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2016-5406 is considered a medium severity vulnerability.
To mitigate CVE-2016-5406, upgrade Red Hat JBoss Enterprise Application Platform to version 7.0.2 or later.
CVE-2016-5406 affects users of Red Hat JBoss Enterprise Application Platform version 7.0.1 and earlier.
CVE-2016-5406 is a privilege escalation vulnerability due to improper RBAC configuration propagation.
Yes, remote authenticated users can exploit CVE-2016-5406 to gain elevated privileges.