CVE-2016-7066
published 2018-09-11CVE-2016-7066: It was found that the improper default permissions on /tmp/auth directory in JBoss Enterprise Application Platform before 7.1.0 can allow any local user to…
PriorityP337high7.8CVSS 3.0
AVLACLPRLUINSUCHIHAH
EPSS
0.30%
22.2th percentile
It was found that the improper default permissions on /tmp/auth directory in JBoss Enterprise Application Platform before 7.1.0 can allow any local user to connect to CLI and allow the user to execute any arbitrary operations.
Affected
2 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| red_hat | jboss_enterprise_application_platform | — | — |
| redhat | jboss_enterprise_application_platform | < 7.1.0 | 7.1.0 |
CVSS provenance
nvdv3.07.8HIGHCVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
nvdv2.04.6MEDIUMAV:L/AC:L/Au:N/C:P/I:P/A:P
vendor_redhat7.8HIGH
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-rwrh-4w4j-q9mq: It was found that the improper default permissions on /tmp/auth directory in JBoss Enterprise Application Platform before 7
ghsa_unreviewed·2022-05-13
CVE-2016-7066 [HIGH] GHSA-rwrh-4w4j-q9mq: It was found that the improper default permissions on /tmp/auth directory in JBoss Enterprise Application Platform before 7
It was found that the improper default permissions on /tmp/auth directory in JBoss Enterprise Application Platform before 7.1.0 can allow any local user to connect to CLI and allow the user to execute any arbitrary operations.
Red Hat
admin-cli: Any local users can connect to jboss-cli
vendor_redhat·2017-12-13·CVSS 7.8
CVE-2016-7066 [HIGH] CWE-266 admin-cli: Any local users can connect to jboss-cli
admin-cli: Any local users can connect to jboss-cli
It was found that the improper default permissions on /tmp/auth directory in JBoss Enterprise Application Platform before 7.1.0 can allow any local user to connect to CLI and allow the user to execute any arbitrary operations.
It was found that the improper default permissions on /tmp/auth directory in EAP 7 can allow any local user to connect to CLI and allow the user to execute any arbitrary operations.
Package: keycloak-admin-client (Red Hat JBoss Enterprise Application Platform 7) - Affected
No detection rules found.
No public exploits indexed.
2018-09-11
Published