CVE-2016-5406: High severity jboss enterprise application platform vulnerability
Escalation of priveleges can occur when a Domain Controller process is managing slave Host Controllers running EAP 6.2, 6.3 or 6.4.
The domain controller will not propagate its administrative RBAC configuration to those slaves, resulting in the slaves (and the servers they manage) granting administrators full administrative privileges.
Other sources
The domain controller in Red Hat JBoss Enterprise Application Platform (EAP) 7.x before 7.0.2 allows remote authenticated users to gain privileges by leveraging failure to propagate administrative RBAC configuration to all slaves.
— MITRE
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2016-5406?
CVE-2016-5406 is considered a medium severity vulnerability.
How do I fix CVE-2016-5406?
To mitigate CVE-2016-5406, upgrade Red Hat JBoss Enterprise Application Platform to version 7.0.2 or later.
Who is affected by CVE-2016-5406?
CVE-2016-5406 affects users of Red Hat JBoss Enterprise Application Platform version 7.0.1 and earlier.
What type of vulnerability is CVE-2016-5406?
CVE-2016-5406 is a privilege escalation vulnerability due to improper RBAC configuration propagation.
Can remote users exploit CVE-2016-5406?
Yes, remote authenticated users can exploit CVE-2016-5406 to gain elevated privileges.