VDB
CVE-2017-12189
CVE-2017-12189
PUBLISHED
CVSS 7.800000190734863 HIGH
It was discovered that the jboss init script as used in Red Hat JBoss Enterprise Application Platform 7.0.7.GA performed unsafe file handling which could result in local privilege escalation. This issue is a result of an incomplete fix for CVE-2016-8656.
EPSS 0.34% · 24.7th percentile
Risk Scores
CVSS 3.0
7.800000190734863
CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
EPSS Score
0.34%
24.7th percentile
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| redhat | enterprise_linux | 6.0, 7.0 |
| Red Hat, Inc. | Red Hat JBoss Enterprise Application Platform | 7.0.7.GA |
| redhat | jboss_enterprise_application_platform | 7.0 |
Timeline
- Jan 10, 2018 CVE Published
- Apr 14, 2021 EPSS Score
- Jun 23, 2021 EPSS Score
- Aug 25, 2021 EPSS Score
- Oct 28, 2021 EPSS Score
- Dec 30, 2021 EPSS Score
- Mar 3, 2022 EPSS Score
- May 5, 2022 EPSS Score
- May 13, 2022 CVE Updated
- Jul 7, 2022 EPSS Score
- Sep 9, 2022 EPSS Score
- Nov 12, 2022 EPSS Score
References
- RHSA-2018:0002 vendor-advisory
- https://nvd.nist.gov/vuln/detail/CVE-2017-12189 advisory
- https://access.redhat.com/errata/RHSA-2018:0005 url
- http://www.securityfocus.com/bid/102407 url
- https://bugzilla.redhat.com/show_bug.cgi?id=CVE-2017-12189 issue
- https://access.redhat.com/errata/RHSA-2018:0003 patch
- https://access.redhat.com/errata/RHSA-2018:0004 patch