First published: Mon Oct 09 2017(Updated: )
It was discovered that the jboss init script as used in Red Hat JBoss Enterprise Application Platform 7.0.7.GA performed unsafe file handling which could result in local privilege escalation. This issue is a result of an incomplete fix for CVE-2016-8656.
Credit: secalert@redhat.com
Affected Software | Affected Version | How to fix |
---|---|---|
Red Hat JBoss Enterprise Application Platform | =7.0 | |
Red Hat Enterprise Linux | =6.0 | |
Red Hat Enterprise Linux | =7.0 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2017-12189 is classified as a medium severity vulnerability due to its potential for local privilege escalation.
To fix CVE-2017-12189, update Red Hat JBoss Enterprise Application Platform to the latest patched version.
CVE-2017-12189 affects the jboss init script in Red Hat JBoss Enterprise Application Platform 7.0.7.GA and Red Hat Enterprise Linux 6.0 and 7.0.
The risks associated with CVE-2017-12189 include unauthorized local privilege escalation that can lead to further exploitation.
Yes, CVE-2017-12189 is the result of an incomplete fix for CVE-2016-8656.