CVE-2016-5406

The domain controller in Red Hat JBoss Enterprise Application Platform (EAP) 7.x before 7.0.2 allows remote authenticated users to gain privileges by leveraging failure to propagate administrative RBAC configuration to all slaves.
Configurations

Configuration 1 (hide)

AND
cpe:2.3:a:redhat:jboss_enterprise_application_platform:*:*:*:*:*:*:*:*
OR cpe:2.3:o:redhat:enterprise_linux:6.0:*:*:*:*:*:*:*
cpe:2.3:o:redhat:enterprise_linux:7.0:*:*:*:*:*:*:*

History

21 Nov 2024, 02:54

Type Values Removed Values Added
References () http://rhn.redhat.com/errata/RHSA-2016-1838.html - Vendor Advisory () http://rhn.redhat.com/errata/RHSA-2016-1838.html - Vendor Advisory
References () http://rhn.redhat.com/errata/RHSA-2016-1839.html - Vendor Advisory () http://rhn.redhat.com/errata/RHSA-2016-1839.html - Vendor Advisory
References () http://rhn.redhat.com/errata/RHSA-2016-1840.html - Vendor Advisory () http://rhn.redhat.com/errata/RHSA-2016-1840.html - Vendor Advisory
References () http://rhn.redhat.com/errata/RHSA-2016-1841.html - Vendor Advisory () http://rhn.redhat.com/errata/RHSA-2016-1841.html - Vendor Advisory
References () https://access.redhat.com/errata/RHSA-2017:3454 - () https://access.redhat.com/errata/RHSA-2017:3454 -
References () https://access.redhat.com/errata/RHSA-2017:3455 - () https://access.redhat.com/errata/RHSA-2017:3455 -
References () https://access.redhat.com/errata/RHSA-2017:3456 - () https://access.redhat.com/errata/RHSA-2017:3456 -
References () https://access.redhat.com/errata/RHSA-2017:3458 - () https://access.redhat.com/errata/RHSA-2017:3458 -
References () https://bugzilla.redhat.com/show_bug.cgi?id=1359014 - Issue Tracking, VDB Entry, Vendor Advisory () https://bugzilla.redhat.com/show_bug.cgi?id=1359014 - Issue Tracking, VDB Entry, Vendor Advisory

Information

Published : 2016-09-26 14:59

Updated : 2024-11-21 02:54


NVD link : CVE-2016-5406

Mitre link : CVE-2016-5406

CVE.ORG link : CVE-2016-5406


JSON object : View

Products Affected

redhat

  • enterprise_linux
  • jboss_enterprise_application_platform
CWE
CWE-264

Permissions, Privileges, and Access Controls