CVE-2017-12167

Related Vulnerabilities: CVE-2017-12167  

It was found that properties based files of the management and the application realm configuration that contain user to role mapping are world readable allowing access to users and roles information to all the users logged in to the system.

It was found that properties based files of the management and the application realm configuration that contain user to role mapping are world readable allowing access to users and roles information to all the users logged in to the system.

Find out more about CVE-2017-12167 from the MITRE CVE dictionary dictionary and NIST NVD.

CVSS v3 metrics

CVSS3 Base Score 5.5
CVSS3 Base Metrics CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
Attack Vector Local
Attack Complexity Low
Privileges Required Low
User Interaction None
Scope Unchanged
Confidentiality High
Integrity Impact None
Availability Impact None

Red Hat Security Errata

Platform Errata Release Date
Red Hat JBoss Enterprise Application Platform 7.0 for RHEL 6 Server (eap7-jboss-ec2-eap) RHSA-2017:3458 2017-12-13
Red Hat JBoss Enterprise Application Platform 7.0 for RHEL 6 Server (eap7-jboss-ec2-eap) RHSA-2018:0005 2018-01-03
Red Hat JBoss Enterprise Application Platform 7.0 for RHEL 7 Server (eap7-jboss-ec2-eap) RHSA-2017:3458 2017-12-13
Red Hat JBoss Enterprise Application Platform 7.0 for RHEL 6 Server RHSA-2018:0002 2018-01-03
Red Hat JBoss EAP 7 RHSA-2018:0003 2018-01-03
Red Hat JBoss Enterprise Application Platform 7.0 for RHEL 6 Server RHSA-2017:3454 2017-12-13
Red Hat JBoss Enterprise Application Platform 7.0 for RHEL 7 Server RHSA-2017:3455 2017-12-13
Red Hat JBoss Enterprise Application Platform 7.0 for RHEL 7 Server RHSA-2018:0004 2018-01-03
Red Hat JBoss Enterprise Application Platform 7.0 for RHEL 7 Server (eap7-jboss-ec2-eap) RHSA-2018:0005 2018-01-03
Red Hat JBoss EAP 7 RHSA-2017:3456 2017-12-13

Acknowledgements

This issue was discovered by Brian Stansberry (Red Hat) and Jeremy Choi (Red Hat).