CVE-2016-6345
published 2016-09-07CVE-2016-6345: RESTEasy allows remote authenticated users to obtain sensitive information by leveraging "insufficient use of random values" in async jobs.
PriorityP431medium6.5CVSS 3.0
AVNACLPRLUINSUCHINAN
EPSS
1.50%
71.4th percentile
RESTEasy allows remote authenticated users to obtain sensitive information by leveraging "insufficient use of random values" in async jobs.
Affected
3 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | resteasy | < resteasy 3.1.0-1 (sid) | resteasy 3.1.0-1 (sid) |
| debian | resteasy3.0 | < resteasy 3.1.0-1 (sid) | resteasy 3.1.0-1 (sid) |
| redhat | resteasy | >= 0 < 3.0.6-3ubuntu0.1~esm1 | 3.0.6-3ubuntu0.1~esm1 |
CVSS provenance
nvdv3.06.5MEDIUMCVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
nvdv2.04.0MEDIUMAV:N/AC:L/Au:S/C:P/I:N/A:N
osv6.5MEDIUM
vendor_debian6.5LOW
vendor_redhat6.5MEDIUM
vendor_ubuntu6.5MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
OSV
resteasy, resteasy3.0 vulnerabilities
osv·2025-07-10·CVSS 6.5
CVE-2016-6345 [MEDIUM] resteasy, resteasy3.0 vulnerabilities
resteasy, resteasy3.0 vulnerabilities
It was discovered that RESTEasy made insufficient use of random values in
asynchronous jobs. An attacker could possibly use this issue to steal
user data. This issue only affected Ubuntu 16.04 LTS. (CVE-2016-6345)
It was discovered that RESTEasy enabled a vulnerable GZIP decompression
module by default. An attacker could possibly use this issue to cause a
denial of service. This issue only affected Ubuntu 16.04 LTS.
(CVE-2016-6346)
It was discovered that RESTEasy improperly made use of unsanitized data
while handling certain errors. An attacker could possibly use this issue
to cause a denial of service or execute arbitrary code.
This issue only affected Ubuntu 16.04 LTS. (CVE-2016-6347)
It was discovered that RESTEasy enabled a vulnerable JSON mani
GHSA
Exposure of Sensitive Information to an Unauthorized Actor in RESTEasy
ghsa·2022-05-17
CVE-2016-6345 [MEDIUM] CWE-200 Exposure of Sensitive Information to an Unauthorized Actor in RESTEasy
Exposure of Sensitive Information to an Unauthorized Actor in RESTEasy
RESTEasy allows remote authenticated users to obtain sensitive information by leveraging "insufficient use of random values" in async jobs.
OSV
Exposure of Sensitive Information to an Unauthorized Actor in RESTEasy
osv·2022-05-17
CVE-2016-6345 [MEDIUM] Exposure of Sensitive Information to an Unauthorized Actor in RESTEasy
Exposure of Sensitive Information to an Unauthorized Actor in RESTEasy
RESTEasy allows remote authenticated users to obtain sensitive information by leveraging "insufficient use of random values" in async jobs.
OSV
CVE-2016-6345: RESTEasy allows remote authenticated users to obtain sensitive information by leveraging "insufficient use of random values" in async jobs
osv·2016-09-07·CVSS 6.5
CVE-2016-6345 [MEDIUM] CVE-2016-6345: RESTEasy allows remote authenticated users to obtain sensitive information by leveraging "insufficient use of random values" in async jobs
RESTEasy allows remote authenticated users to obtain sensitive information by leveraging "insufficient use of random values" in async jobs.
Ubuntu
RESTEasy vulnerabilities
vendor_ubuntu·2025-07-10·CVSS 6.5
CVE-2021-20289 [MEDIUM] RESTEasy vulnerabilities
Title: RESTEasy vulnerabilities
Summary: Several security issues were fixed in resteasy, resteasy3.0.
It was discovered that RESTEasy made insufficient use of random values in
asynchronous jobs. An attacker could possibly use this issue to steal
user data. This issue only affected Ubuntu 14.04 LTS. (CVE-2016-6345)
It was discovered that RESTEasy enabled a vulnerable GZIP decompression
module by default. An attacker could possibly use this issue to cause a
denial of service. This issue only affected Ubuntu 14.04 LTS.
(CVE-2016-6346)
It was discovered that RESTEasy improperly made use of unsanitized data
while handling certain errors. An attacker could possibly use this issue
to cause a denial of service or execute arbitrary code.
This issue only affected Ubuntu 14.04 LTS. (CVE-2016-6347
Red Hat
RESTEasy: Insufficient use of random values in RESTEasy async jobs could lead to loss of data confidentiality
vendor_redhat·2016-09-01·CVSS 6.5
CVE-2016-6345 [MEDIUM] CWE-330 RESTEasy: Insufficient use of random values in RESTEasy async jobs could lead to loss of data confidentiality
RESTEasy: Insufficient use of random values in RESTEasy async jobs could lead to loss of data confidentiality
RESTEasy allows remote authenticated users to obtain sensitive information by leveraging "insufficient use of random values" in async jobs.
It was found that there was insufficient use of randam values in RESTEasy async jobs. An attacker could use this flaw to steal user data.
Mitigation: Don't enable Async Jobs Service as details in the section, "2.10. RESTEASY ASYNCHRONOUS JOB SERVICE" of JBoss EAP 7 Developing Web Services Applications documentation: https://access.redhat.com/documentation/en/red-hat-jboss-enterprise-application-platform/7.0/paged/developing-web-services-applications/chapter-2-developing-jax-rs-web-services
Package: resteasy (Red Hat BPM Suite 6) - Will not
Debian
CVE-2016-6345: resteasy - RESTEasy allows remote authenticated users to obtain sensitive information by le...
vendor_debian·2016·CVSS 6.5
CVE-2016-6345 [MEDIUM] CVE-2016-6345: resteasy - RESTEasy allows remote authenticated users to obtain sensitive information by le...
RESTEasy allows remote authenticated users to obtain sensitive information by leveraging "insufficient use of random values" in async jobs.
Scope: local
sid: resolved (fixed in 3.1.0-1)
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2016-6345 RESTEasy: Insufficient use of random values in RESTEasy async jobs could lead to loss of data confidentiality [fedora-all]
bugzilla·2017-07-14·CVSS 6.5
CVE-2016-6345 [MEDIUM] CVE-2016-6345 RESTEasy: Insufficient use of random values in RESTEasy async jobs could lead to loss of data confidentiality [fedora-all]
CVE-2016-6345 RESTEasy: Insufficient use of random values in RESTEasy async jobs could lead to loss of data confidentiality [fedora-all]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected versions
of fedora-all.
For comments that are specific to the vulnerability please use bugs filed
against the "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When submitting as an update, use the fedpkg template provided in the next
comment(s). This will include the bug IDs of this tracking bug as well as
the relevant top-level CVE bugs.
Please also mention the CVE IDs being fixed in the RPM changelog and the
fedpkg commit mes
Bugzilla
CVE-2016-6345 RESTEasy: Insufficient use of random values in RESTEasy async jobs could lead to loss of data confidentiality
bugzilla·2016-09-01·CVSS 6.5
CVE-2016-6345 [MEDIUM] CVE-2016-6345 RESTEasy: Insufficient use of random values in RESTEasy async jobs could lead to loss of data confidentiality
CVE-2016-6345 RESTEasy: Insufficient use of random values in RESTEasy async jobs could lead to loss of data confidentiality
It was found that there was insufficient use of randam values in RESTEasy async jobs. An attacker could use this flaw to steal user data.
Discussion:
Acknowledgments:
Name: Mikhail Egorov (Odin)
---
Created resteasy tracking bugs for this issue:
Affects: fedora-all [bug 1372118]
---
Mitigation:
Don't enable Async Jobs Service as details in the section, "2.10. RESTEASY ASYNCHRONOUS JOB SERVICE" of JBoss EAP 7 Developing Web Services Applications documentation: https://access.redhat.com/documentation/en/red-hat-jboss-enterprise-application-platform/7.0/paged/developing-web-services-applications/chapter-2-developing-jax-rs-web-services
---
Created resteasy tr
Bugzilla
CVE-2016-6345 RESTEasy: Insufficient use of random values in RESTEasy async jobs could lead to loss of data confidentiality [fedora-all]
bugzilla·2016-09-01·CVSS 6.5
CVE-2016-6345 [MEDIUM] CVE-2016-6345 RESTEasy: Insufficient use of random values in RESTEasy async jobs could lead to loss of data confidentiality [fedora-all]
CVE-2016-6345 RESTEasy: Insufficient use of random values in RESTEasy async jobs could lead to loss of data confidentiality [fedora-all]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected versions
of Fedora.
For comments that are specific to the vulnerability please use bugs filed
against the "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When submitting as an update, use the fedpkg template provided in the next
comment(s). This will include the bug IDs of this tracking bug as well as
the relevant top-level CVE bugs.
Please also mention the CVE IDs being fixed in the RPM changelog and the
fedpkg commit message
2016-09-07
Published