CVE-2017-12167Incorrect Permission Assignment in Redhat Jboss Enterprise Application Platform

Severity
5.5MEDIUMNVD
EPSS
0.1%
top 83.96%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedJul 26
Latest updateMay 13

Description

It was found in EAP 7 before 7.0.9 that properties based files of the management and the application realm configuration that contain user to role mapping are world readable allowing access to users and roles information to all the users logged in to the system.

CVSS vector

CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:NExploitability: 1.8 | Impact: 3.6

Affected Packages2 packages

🔴Vulnerability Details

2
GHSA
GHSA-5gp7-3qfp-8548: It was found in EAP 7 before 72022-05-13
CVEList
CVE-2017-12167: It was found in EAP 7 before 72018-07-26

📋Vendor Advisories

1
Red Hat
EAP-7: Wrong privileges on multiple property files2017-09-14

💬Community

1
Bugzilla
CVE-2017-12167 EAP-7: Wrong privileges on multiple property files2017-09-14
CVE-2017-12167 — Incorrect Permission Assignment | cvebase