Vulnerability Name: | CVE-2016-5422 (CCN-116760) | ||||||||||||
Assigned: | 2016-07-31 | ||||||||||||
Published: | 2016-07-31 | ||||||||||||
Updated: | 2016-09-08 | ||||||||||||
Summary: | The web console in Red Hat JBoss Operations Network (JON) before 3.3.7 does not properly authorize requests to add users with the super user role, which allows remote authenticated users to gain admin privileges via a crafted POST request. | ||||||||||||
CVSS v3 Severity: | 8.8 High (CVSS v3.1 Vector: CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H) 7.7 High (Temporal CVSS v3.1 Vector: CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H/E:U/RL:O/RC:C)
7.7 High (CCN Temporal CVSS v3.1 Vector: CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H/E:U/RL:O/RC:C)
| ||||||||||||
CVSS v2 Severity: | 6.5 Medium (CVSS v2 Vector: AV:N/AC:L/Au:S/C:P/I:P/A:P)
| ||||||||||||
Vulnerability Type: | CWE-264 | ||||||||||||
Vulnerability Consequences: | Gain Privileges | ||||||||||||
References: | Source: MITRE Type: CNA CVE-2016-5422 Source: CCN Type: RHSA-2016-1785 Moderate: Red Hat JBoss Operations Network 3.3.7 security and bug fix update Source: REDHAT Type: Patch, Vendor Advisory RHSA-2016:1785 Source: BID Type: Third Party Advisory, VDB Entry 92722 Source: CCN Type: BID-92722 Red Hat JBoss Operations Network CVE-2016-5422 Remote Privilege Escalation Vulnerability Source: CCN Type: Red Hat Bugzilla Bug 1361933 (CVE-2016-5422) CVE-2016-5422 JON3: privilege escalation via improper authorization Source: XF Type: UNKNOWN redhat-jon-cve20165422-priv-esc(116760) Source: CCN Type: Red Hat Security - RHSA-2016:1785-1 Red Hat JBoss Operations Network 3.3.7 security and bug fix update | ||||||||||||
Vulnerable Configuration: | Configuration 1: Configuration CCN 1: ![]() | ||||||||||||
BACK |