ZeroHour

CVE-2016-5422

CVSS 3.0
8.8 high
EPSS
2%p81
Published
()
Modified
Description

The web console in Red Hat JBoss Operations Network (JON) before 3.3.7 does not properly authorize requests to add users with the super user role, which allows remote authenticated users to gain admin privileges via a crafted POST request.

Vendors
redhat
Products
jboss operations network
Weakness
CWE-264
Vector
CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

In the news

No ingested article mentions this CVE yet.