CVE-2016-7061
published 2018-09-10CVE-2016-7061: An information disclosure vulnerability was found in JBoss Enterprise Application Platform before 7.0.4. It was discovered that when configuring RBAC and…
PriorityP431medium6.5CVSS 3.0
AVNACLPRLUINSUCHINAN
EPSS
1.77%
75.6th percentile
An information disclosure vulnerability was found in JBoss Enterprise Application Platform before 7.0.4. It was discovered that when configuring RBAC and marking information as sensitive, users with a Monitor role are able to view the sensitive information.
Affected
2 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| red_hat | eap | — | — |
| redhat | jboss_enterprise_application_platform | < 7.0.4 | 7.0.4 |
CVSS provenance
nvdv3.06.5MEDIUMCVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
nvdv2.04.0MEDIUMAV:N/AC:L/Au:S/C:P/I:N/A:N
vendor_redhat3.5LOW
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Red Hat
EAP: Sensitive data can be exposed at the server level in domain mode
vendor_redhat·2016-11-07·CVSS 3.5
CVE-2016-7061 [LOW] CWE-200 EAP: Sensitive data can be exposed at the server level in domain mode
EAP: Sensitive data can be exposed at the server level in domain mode
An information disclosure vulnerability was found in JBoss Enterprise Application Platform before 7.0.4. It was discovered that when configuring RBAC and marking information as sensitive, users with a Monitor role are able to view the sensitive information.
It was discovered that when configuring RBAC and marking information as sensitive, users with a Monitor role are able to view the sensitive information.
GHSA
GHSA-35gg-hfjv-3g6c: An information disclosure vulnerability was found in JBoss Enterprise Application Platform before 7
ghsa_unreviewed·2022-05-13
CVE-2016-7061 [MEDIUM] CWE-200 GHSA-35gg-hfjv-3g6c: An information disclosure vulnerability was found in JBoss Enterprise Application Platform before 7
An information disclosure vulnerability was found in JBoss Enterprise Application Platform before 7.0.4. It was discovered that when configuring RBAC and marking information as sensitive, users with a Monitor role are able to view the sensitive information.
No detection rules found.
No public exploits indexed.
http://rhn.redhat.com/errata/RHSA-2017-0170.htmlhttp://rhn.redhat.com/errata/RHSA-2017-0171.htmlhttp://rhn.redhat.com/errata/RHSA-2017-0172.htmlhttp://rhn.redhat.com/errata/RHSA-2017-0173.htmlhttp://rhn.redhat.com/errata/RHSA-2017-0244.htmlhttp://rhn.redhat.com/errata/RHSA-2017-0245.htmlhttp://rhn.redhat.com/errata/RHSA-2017-0246.htmlhttp://rhn.redhat.com/errata/RHSA-2017-0247.htmlhttp://rhn.redhat.com/errata/RHSA-2017-0250.htmlhttp://www.securityfocus.com/bid/94222https://access.redhat.com/errata/RHSA-2017:3454https://access.redhat.com/errata/RHSA-2017:3455https://access.redhat.com/errata/RHSA-2017:3456https://access.redhat.com/errata/RHSA-2017:3458https://bugzilla.redhat.com/show_bug.cgi?id=CVE-2016-7061http://rhn.redhat.com/errata/RHSA-2017-0170.htmlhttp://rhn.redhat.com/errata/RHSA-2017-0171.htmlhttp://rhn.redhat.com/errata/RHSA-2017-0172.htmlhttp://rhn.redhat.com/errata/RHSA-2017-0173.htmlhttp://rhn.redhat.com/errata/RHSA-2017-0244.htmlhttp://rhn.redhat.com/errata/RHSA-2017-0245.htmlhttp://rhn.redhat.com/errata/RHSA-2017-0246.htmlhttp://rhn.redhat.com/errata/RHSA-2017-0247.htmlhttp://rhn.redhat.com/errata/RHSA-2017-0250.htmlhttp://www.securityfocus.com/bid/94222https://access.redhat.com/errata/RHSA-2017:3454https://access.redhat.com/errata/RHSA-2017:3455https://access.redhat.com/errata/RHSA-2017:3456https://access.redhat.com/errata/RHSA-2017:3458https://bugzilla.redhat.com/show_bug.cgi?id=CVE-2016-7061
2018-09-10
Published