CVE-2016-8627: Medium severity jboss enterprise application platform vulnerability
admin-cli before versions 3.0.0.alpha25, 2.2.1.cr2 is vulnerable to an EAP feature to download server log files that allows logs to be available via GET requests making them vulnerable to cross-origin attacks. An attacker could trigger the user's browser to request the log files consuming enough resources that normal server functioning could be impaired.
Other sources
Potential EAP resource starvation DOS attack via GET requests for server log files
— Red Hat
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2016-8627?
CVE-2016-8627 is considered a moderate severity vulnerability due to its characteristics that could lead to exposure of sensitive log files.
How do I fix CVE-2016-8627?
To fix CVE-2016-8627, you should upgrade to admin-cli version 3.0.0.alpha25 or 2.2.1.cr2 or later.
What versions are affected by CVE-2016-8627?
CVE-2016-8627 affects admin-cli versions prior to 3.0.0.alpha25 and 2.2.1.cr2.
What types of attacks can CVE-2016-8627 facilitate?
CVE-2016-8627 can facilitate cross-origin requests allowing unauthorized access to server log files.
Is CVE-2016-8627 related to other vulnerabilities?
CVE-2016-8627 is related to the use of log downloading features in administrative interfaces that expose sensitive information.