Back

HIGH

jboss: jbossas: unsafe chown of server.log in jboss init script allows privilege escalation

Published May 22, 2018

Description

Jboss jbossas before versions 5.2.0-23, 6.4.13, 7.0.5 is vulnerable to an unsafe file handling in the jboss init script which could result in local privilege escalation.

Affected products

Remediation

Red Hat statement

It was found that a variant of the Tomcat CVE-2016-1240 exploit is also applicable to Red Hat JBoss Enterprise Application Platform 5, 6, and 7. CVE-2016-8656 addresses these problems with JBoss EAP. The issue is now corrected in the various versions of Red Hat JBoss Enterprise Application Platform including EAP 6.4.13 and EAP 7.0.5. For further information please refer to https://access.redhat.com/articles/3016681

Metrics

Weaknesses (2)

References (17)

Change history (0)

No recorded changes yet.

Sources
CVE.org / MITRE
Status PUBLISHED
Assigner redhat
Published May 22, 2018
Updated Aug 6, 2024
Reserved Oct 12, 2016
NVD
Status Modified
Modified Jun 17, 2026
Red Hat
Severity Important
Public date Sep 15, 2016