VDB
CVE-2016-5406
CVE-2016-5406
PUBLISHED
CVSS 8.800000190734863 HIGH
The domain controller in Red Hat JBoss Enterprise Application Platform (EAP) 7.x before 7.0.2 allows remote authenticated users to gain privileges by leveraging failure to propagate administrative RBAC configuration to all slaves.
EPSS 2.90% · 86.3th percentile
Risk Scores
CVSS 3.0
8.800000190734863
CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
EPSS Score
2.90%
86.3th percentile
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| n/a | n/a | * |
| redhat | jboss_enterprise_application_platform | 0 |
Timeline
- Sep 26, 2016 CVE Published
- Feb 4, 2022 EPSS Score
- Mar 29, 2022 EPSS Score
- May 21, 2022 EPSS Score
- Sep 5, 2022 EPSS Score
- Oct 28, 2022 EPSS Score
- Dec 20, 2022 EPSS Score
- Feb 11, 2023 EPSS Score
- Mar 7, 2023 EPSS Score
- Apr 5, 2023 EPSS Score
- Jul 20, 2023 EPSS Score
- Sep 11, 2023 EPSS Score
References
- RHSA-2017:3456 vendor-advisory
- RHSA-2016:1841 vendor-advisory
- RHSA-2017:3458 vendor-advisory
- http://rhn.redhat.com/errata/RHSA-2016-1838.html advisory
- https://access.redhat.com/errata/RHSA-2017:3454 technical
- https://access.redhat.com/errata/RHSA-2017:3455 technical
- http://rhn.redhat.com/errata/RHSA-2016-1840.html advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=1359014 issue
- https://nvd.nist.gov/vuln/detail/CVE-2016-5406 advisory
- http://rhn.redhat.com/errata/RHSA-2016-1839.html url