CVE-2017-12167: Infoleak
It was found in EAP 7 before 7.0.9 that properties based files of the management and the application realm configuration that contain user to role mapping are world readable allowing access to users and roles information to all the users logged in to the system.
Other sources
It was found that properties based files of the management and the application realm configuration that contain user to role mapping are world readable allowing access to users and roles information to all the users logged in to the system.
— Red Hat
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2017-12167?
CVE-2017-12167 is considered a high-severity vulnerability due to the exposure of sensitive user and role mapping information.
How do I fix CVE-2017-12167?
To fix CVE-2017-12167, upgrade to a version of JBoss Enterprise Application Platform that is 7.0.9 or later.
What systems are affected by CVE-2017-12167?
CVE-2017-12167 affects JBoss Enterprise Application Platform versions prior to 7.0.9 and the exact version 7.1.0.
What impact does CVE-2017-12167 have on user data?
CVE-2017-12167 can lead to unauthorized access to user role mapping data, potentially compromising security.
Is there a workaround for CVE-2017-12167 if I cannot upgrade?
There is no official workaround for CVE-2017-12167, and upgrading is the recommended action to mitigate the risk.