ZeroHour

CVE-2017-12167

CVSS 3.0
5.5 medium
EPSS
<1%p31
Published
()
Modified
Description

It was found in EAP 7 before 7.0.9 that properties based files of the management and the application realm configuration that contain user to role mapping are world readable allowing access to users and roles information to all the users logged in to the system.

Vendors
redhat
Products
jboss enterprise application platform
Weakness
CWE-732, CWE-200
Vector
CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N

In the news

No ingested article mentions this CVE yet.