CVE-2016-5406

Impact:
Moderate
Public Date:
2016-07-26
Bugzilla:
1359014: CVE-2016-5406 EAP7 Privilege escalation when managing domain including earlier version slaves
The domain controller will not propagate its administrative RBAC configuration to some slaves. An attacker could use this to escalate their privileges.

Find out more about CVE-2016-5406 from the MITRE CVE dictionary dictionary and NIST NVD.

CVSS v2 metrics

Base Score 7
Base Metrics AV:A/AC:M/Au:S/C:P/I:C/A:C
Access Vector Adjacent Network
Access Complexity Medium
Authentication Single
Confidentiality Impact Partial
Integrity Impact Complete
Availability Impact Complete

CVSS v3 metrics

CVSS3 Base Score 7.5
CVSS3 Base Metrics CVSS:3.0/AV:A/AC:H/PR:L/UI:R/S:C/C:L/I:H/A:H
Attack Vector Adjacent Network
Attack Complexity High
Privileges Required Low
User Interaction Required
Scope Changed
Confidentiality Low
Integrity Impact High
Availability Impact High

Find out more about Red Hat support for the Common Vulnerability Scoring System (CVSS).

Red Hat Security Errata

Platform Errata Release Date
Red Hat JBoss Enterprise Application Platform 7.0 for RHEL 6 Server (eap7-jboss-ec2-eap) RHSA-2017:3458 2017-12-13
Red Hat JBoss Enterprise Application Platform 7.0 for RHEL 6 Server RHSA-2016:1838 2016-09-08
Red Hat JBoss Enterprise Application Platform 7.0 for RHEL 6 Server RHSA-2017:3454 2017-12-13
Red Hat JBoss Enterprise Application Platform 7.0 for RHEL 7 Server RHSA-2017:3455 2017-12-13
Red Hat JBoss Enterprise Application Platform 7.0 for RHEL 7 Server (eap7-jboss-ec2-eap) RHSA-2017:3458 2017-12-13
Red Hat JBoss EAP 7 RHSA-2016:1841 2016-09-08
Red Hat JBoss Enterprise Application Platform 7.0 for RHEL 7 Server RHSA-2016:1839 2016-09-08
Red Hat JBoss Enterprise Application Platform 7.0 for RHEL 6 Server (eap7-jboss-ec2-eap) RHSA-2016:1840 2016-09-08
Red Hat JBoss EAP 7 RHSA-2017:3456 2017-12-13
Red Hat JBoss Enterprise Application Platform 7.0 for RHEL 7 Server (eap7-jboss-ec2-eap) RHSA-2016:1840 2016-09-08

Acknowledgements

This issue was discovered by Tomaz Cerar (Red Hat).

Last Modified
Close

Welcome! Check out the Getting Started with Red Hat page for quick tours and guides for common tasks.