CVE-2016-8656
published 2018-05-22CVE-2016-8656: Jboss jbossas before versions 5.2.0-23, 6.4.13, 7.0.5 is vulnerable to an unsafe file handling in the jboss init script which could result in local privilege…
PriorityP338high7.8CVSS 3.0
AVLACLPRLUINSUCHIHAH
EPSS
0.37%
28.9th percentile
Jboss jbossas before versions 5.2.0-23, 6.4.13, 7.0.5 is vulnerable to an unsafe file handling in the jboss init script which could result in local privilege escalation.
Affected
9 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| red_hat_inc | red_hat_jboss_enterprise_application_platform | — | — |
| redhat | enterprise_linux | — | — |
| redhat | enterprise_linux | — | — |
| redhat | jboss_enterprise_application_platform | — | — |
| redhat | jboss_enterprise_application_platform | — | — |
| redhat | jboss_enterprise_application_platform | — | — |
| redhat | jboss_enterprise_application_platform | — | — |
| redhat | jboss_enterprise_application_platform | — | — |
| redhat | jboss_enterprise_application_platform | — | — |
CVSS provenance
nvdv3.07.8HIGHCVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
nvdv2.04.6MEDIUMAV:L/AC:L/Au:N/C:P/I:P/A:P
vendor_redhat7.8HIGH
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Red Hat
jboss: unsafe chown of server.log in jboss init script allows privilege escalation (Incomplete fix for CVE-2016-8656)
vendor_redhat·2018-01-03·CVSS 7.0
CVE-2017-12189 [HIGH] jboss: unsafe chown of server.log in jboss init script allows privilege escalation (Incomplete fix for CVE-2016-8656)
jboss: unsafe chown of server.log in jboss init script allows privilege escalation (Incomplete fix for CVE-2016-8656)
It was discovered that the jboss init script as used in Red Hat JBoss Enterprise Application Platform 7.0.7.GA performed unsafe file handling which could result in local privilege escalation. This issue is a result of an incomplete fix for CVE-2016-8656.
It was discovered that the jboss init script performed unsafe file handling which could result in local privilege escalation.
Red Hat
jboss: jbossas: unsafe chown of server.log in jboss init script allows privilege escalation
vendor_redhat·2016-09-15·CVSS 7.8
CVE-2016-8656 [HIGH] CWE-284 jboss: jbossas: unsafe chown of server.log in jboss init script allows privilege escalation
jboss: jbossas: unsafe chown of server.log in jboss init script allows privilege escalation
Jboss jbossas before versions 5.2.0-23, 6.4.13, 7.0.5 is vulnerable to an unsafe file handling in the jboss init script which could result in local privilege escalation.
It was discovered that the jboss init script performed unsafe file handling which could result in local privilege escalation.
Statement: It was found that a variant of the Tomcat CVE-2016-1240 exploit is also applicable to Red Hat JBoss Enterprise Application Platform 5, 6, and 7. CVE-2016-8656 addresses these problems with JBoss EAP. The issue is now corrected in the various versions of Red Hat JBoss Enterprise Application Platform including EAP 6.4.13 and EAP 7.0.5. For further information please refer to https://access.redhat.
GHSA
GHSA-v2jx-53jj-4vjf: Jboss jbossas before versions 5
ghsa_unreviewed·2022-05-13
CVE-2016-8656 [HIGH] GHSA-v2jx-53jj-4vjf: Jboss jbossas before versions 5
Jboss jbossas before versions 5.2.0-23, 6.4.13, 7.0.5 is vulnerable to an unsafe file handling in the jboss init script which could result in local privilege escalation.
GHSA
GHSA-g689-52m8-86fh: It was discovered that the jboss init script as used in Red Hat JBoss Enterprise Application Platform 7
ghsa_unreviewed·2022-05-13·CVSS 7.0
CVE-2017-12189 [HIGH] GHSA-g689-52m8-86fh: It was discovered that the jboss init script as used in Red Hat JBoss Enterprise Application Platform 7
It was discovered that the jboss init script as used in Red Hat JBoss Enterprise Application Platform 7.0.7.GA performed unsafe file handling which could result in local privilege escalation. This issue is a result of an incomplete fix for CVE-2016-8656.
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2017-12189 jboss: unsafe chown of server.log in jboss init script allows privilege escalation (Incomplete fix for CVE-2016-8656)
bugzilla·2017-10-09·CVSS 7.0
CVE-2017-12189 [HIGH] CVE-2017-12189 jboss: unsafe chown of server.log in jboss init script allows privilege escalation (Incomplete fix for CVE-2016-8656)
CVE-2017-12189 jboss: unsafe chown of server.log in jboss init script allows privilege escalation (Incomplete fix for CVE-2016-8656)
It was reported that the jbossas init script performed unsafe file handling, which could result in local privilege escalation.
Discussion:
This issue has been addressed in the following products:
Red Hat JBoss Enterprise Application Platform
Via RHSA-2018:0003 https://access.redhat.com/errata/RHSA-2018:0003
---
This issue has been addressed in the following products:
Red Hat JBoss Enterprise Application Platform 7.0 for RHEL 6
Via RHSA-2018:0002 https://access.redhat.com/errata/RHSA-2018:0002
---
This issue has been addressed in the following products:
Red Hat JBoss Enterprise Application Platform 7.0 for RHEL 7
Via RHSA-2018:0004 https://access.
Bugzilla
CVE-2016-8656 jboss: jbossas: unsafe chown of server.log in jboss init script allows privilege escalation
bugzilla·2016-11-30·CVSS 7.8
CVE-2016-8656 [HIGH] CVE-2016-8656 jboss: jbossas: unsafe chown of server.log in jboss init script allows privilege escalation
CVE-2016-8656 jboss: jbossas: unsafe chown of server.log in jboss init script allows privilege escalation
It was reported that the jbossas init script performed unsafe file handling, which could result in local privilege escalation.
Discussion:
This issue has been addressed in the following products:
Via RHSA-2017:0247 https://rhn.redhat.com/errata/RHSA-2017-0247.html
---
This issue has been addressed in the following products:
Red Hat JBoss Enterprise Application Platform 6.4 for RHEL 5
Via RHSA-2017:0246 https://rhn.redhat.com/errata/RHSA-2017-0246.html
---
This issue has been addressed in the following products:
Red Hat JBoss Enterprise Application Platform 6.4 for RHEL 7
Via RHSA-2017:0245 https://rhn.redhat.com/errata/RHSA-2017-0245.html
---
This issue has been addresse
http://rhn.redhat.com/errata/RHSA-2017-0244.htmlhttp://rhn.redhat.com/errata/RHSA-2017-0245.htmlhttp://rhn.redhat.com/errata/RHSA-2017-0246.htmlhttp://rhn.redhat.com/errata/RHSA-2017-0250.htmlhttp://rhn.redhat.com/errata/RHSA-2017-0831.htmlhttp://rhn.redhat.com/errata/RHSA-2017-0832.htmlhttp://rhn.redhat.com/errata/RHSA-2017-0834.htmlhttp://www.securityfocus.com/bid/96035https://access.redhat.com/errata/RHSA-2017:3454https://access.redhat.com/errata/RHSA-2017:3455https://access.redhat.com/errata/RHSA-2017:3458https://access.redhat.com/errata/RHSA-2018:1609https://bugzilla.redhat.com/show_bug.cgi?id=CVE-2016-8656http://rhn.redhat.com/errata/RHSA-2017-0244.htmlhttp://rhn.redhat.com/errata/RHSA-2017-0245.htmlhttp://rhn.redhat.com/errata/RHSA-2017-0246.htmlhttp://rhn.redhat.com/errata/RHSA-2017-0250.htmlhttp://rhn.redhat.com/errata/RHSA-2017-0831.htmlhttp://rhn.redhat.com/errata/RHSA-2017-0832.htmlhttp://rhn.redhat.com/errata/RHSA-2017-0834.htmlhttp://www.securityfocus.com/bid/96035https://access.redhat.com/errata/RHSA-2017:3454https://access.redhat.com/errata/RHSA-2017:3455https://access.redhat.com/errata/RHSA-2017:3458https://access.redhat.com/errata/RHSA-2018:1609https://bugzilla.redhat.com/show_bug.cgi?id=CVE-2016-8656
2018-05-22
Published