CVE-2016-7061
EAP: Sensitive data can be exposed at the server level in domain mode
Severity Score
6.5
*CVSS v3
Exploit Likelihood
*EPSS
Affected Versions
*CPE
Public Exploits
0
*Multiple Sources
Exploited in Wild
-
*KEV
Decision
-
*SSVC
Descriptions
An information disclosure vulnerability was found in JBoss Enterprise Application Platform before 7.0.4. It was discovered that when configuring RBAC and marking information as sensitive, users with a Monitor role are able to view the sensitive information.
Se ha detectado una vulnerabilidad de divulgación de información en JBoss Enterprise Application Platform en versiones anteriores a la 7.0.4. Se ha descubierto que, al configurar RBAC y marcar información como sensible, los usuarios con rol Monitor pueden visualizar dicha información sensible
It was discovered that when configuring RBAC and marking information as sensitive, users with a Monitor role are able to view the sensitive information.
*Credits:
N/A
CVSS Scores
Attack Vector
Attack Complexity
Privileges Required
User Interaction
Scope
Confidentiality
Integrity
Availability
Attack Vector
Attack Complexity
Privileges Required
User Interaction
Scope
Confidentiality
Integrity
Availability
Attack Vector
Attack Complexity
Authentication
Confidentiality
Integrity
Availability
* Common Vulnerability Scoring System
SSVC
- Decision:-
Exploitation
Automatable
Tech. Impact
* Organization's Worst-case Scenario
Timeline
- 2016-08-23 CVE Reserved
- 2017-01-19 CVE Published
- 2024-06-25 EPSS Updated
- 2024-08-06 CVE Updated
- ---------- Exploited in Wild
- ---------- KEV Due Date
- ---------- First Exploit
CWE
- CWE-200: Exposure of Sensitive Information to an Unauthorized Actor
CAPEC
References (17)
URL | Tag | Source |
---|---|---|
http://www.securityfocus.com/bid/94222 | Third Party Advisory |
URL | Date | SRC |
---|
URL | Date | SRC |
---|
URL | Date | SRC |
---|---|---|
http://rhn.redhat.com/errata/RHSA-2017-0170.html | 2023-11-07 | |
http://rhn.redhat.com/errata/RHSA-2017-0171.html | 2023-11-07 | |
http://rhn.redhat.com/errata/RHSA-2017-0172.html | 2023-11-07 | |
http://rhn.redhat.com/errata/RHSA-2017-0173.html | 2023-11-07 | |
http://rhn.redhat.com/errata/RHSA-2017-0244.html | 2023-11-07 | |
http://rhn.redhat.com/errata/RHSA-2017-0245.html | 2023-11-07 | |
http://rhn.redhat.com/errata/RHSA-2017-0246.html | 2023-11-07 | |
http://rhn.redhat.com/errata/RHSA-2017-0247.html | 2023-11-07 | |
http://rhn.redhat.com/errata/RHSA-2017-0250.html | 2023-11-07 | |
https://access.redhat.com/errata/RHSA-2017:3454 | 2023-11-07 | |
https://access.redhat.com/errata/RHSA-2017:3455 | 2023-11-07 | |
https://access.redhat.com/errata/RHSA-2017:3456 | 2023-11-07 | |
https://access.redhat.com/errata/RHSA-2017:3458 | 2023-11-07 | |
https://bugzilla.redhat.com/show_bug.cgi?id=CVE-2016-7061 | 2023-11-07 | |
https://access.redhat.com/security/cve/CVE-2016-7061 | 2017-12-13 | |
https://bugzilla.redhat.com/show_bug.cgi?id=1380852 | 2017-12-13 |
Affected Vendors, Products, and Versions
Vendor | Product | Version | Other | Status | ||||||
---|---|---|---|---|---|---|---|---|---|---|
Vendor | Product | Version | Other | Status | <-- --> | Vendor | Product | Version | Other | Status |
Redhat Search vendor "Redhat" | Jboss Enterprise Application Platform Search vendor "Redhat" for product "Jboss Enterprise Application Platform" | < 7.0.4 Search vendor "Redhat" for product "Jboss Enterprise Application Platform" and version " < 7.0.4" | - |
Affected
| in | Redhat Search vendor "Redhat" | Enterprise Linux Search vendor "Redhat" for product "Enterprise Linux" | 6.0 Search vendor "Redhat" for product "Enterprise Linux" and version "6.0" | - |
Safe
|
Redhat Search vendor "Redhat" | Jboss Enterprise Application Platform Search vendor "Redhat" for product "Jboss Enterprise Application Platform" | < 7.0.4 Search vendor "Redhat" for product "Jboss Enterprise Application Platform" and version " < 7.0.4" | - |
Affected
| in | Redhat Search vendor "Redhat" | Enterprise Linux Search vendor "Redhat" for product "Enterprise Linux" | 7.0 Search vendor "Redhat" for product "Enterprise Linux" and version "7.0" | - |
Safe
|