Bug 1359014 (CVE-2016-5406) - CVE-2016-5406 EAP7 Privilege escalation when managing domain including earlier version slaves
Summary: CVE-2016-5406 EAP7 Privilege escalation when managing domain including earlie...
Status: CLOSED NOTABUG
Alias: CVE-2016-5406
Product: Security Response
Classification: Other
Component: vulnerability
Version: unspecified
Hardware: All
OS: Linux
medium
medium
Target Milestone: ---
Assignee: Red Hat Product Security
QA Contact:
URL:
Whiteboard: impact=moderate,public=20160726,repor...
Keywords: Security
Depends On:
Blocks: 1359008 1520314
TreeView+ depends on / blocked
 
Reported: 2016-07-22 06:03 UTC by Jason Shepherd
Modified: 2019-06-11 11:13 UTC (History)
19 users (show)

(edit)
The domain controller will not propagate its administrative RBAC configuration to some slaves. An attacker could use this to escalate their privileges.
Clone Of:
(edit)
Last Closed: 2019-06-08 02:56:25 UTC


Attachments (Terms of Use)


External Trackers
Tracker ID Priority Status Summary Last Updated
Red Hat Product Errata RHSA-2016:1838 normal SHIPPED_LIVE Important: JBoss Enterprise Application Platform 7.0.2 on RHEL 6 2016-09-08 22:17:08 UTC
Red Hat Product Errata RHSA-2016:1839 normal SHIPPED_LIVE Important: JBoss Enterprise Application Platform 7.0.2 for RHEL 7 2016-09-08 22:38:52 UTC
Red Hat Product Errata RHSA-2016:1840 normal SHIPPED_LIVE Important: eap7-jboss-ec2-eap security, bug fix, and enhancement update 2016-09-08 22:14:07 UTC
Red Hat Product Errata RHSA-2016:1841 normal SHIPPED_LIVE Important: JBoss Enterprise Application Platform 7.0.2 2016-09-08 22:12:58 UTC
Red Hat Product Errata RHSA-2017:3454 normal SHIPPED_LIVE Important: Red Hat JBoss Enterprise Application Platform 7.1.0 security update 2017-12-13 22:48:09 UTC
Red Hat Product Errata RHSA-2017:3455 normal SHIPPED_LIVE Important: Red Hat JBoss Enterprise Application Platform 7.1.0 security update 2017-12-13 22:57:25 UTC
Red Hat Product Errata RHSA-2017:3456 normal SHIPPED_LIVE Important: Red Hat JBoss Enterprise Application Platform 7.1.0 security update 2017-12-13 22:31:03 UTC
Red Hat Product Errata RHSA-2017:3458 normal SHIPPED_LIVE Important: eap7-jboss-ec2-eap security update 2017-12-13 23:26:13 UTC

Description Jason Shepherd 2016-07-22 06:03:20 UTC
Escalation of priveleges can occur when a Domain Controller process is managing slave Host Controllers running EAP 6.2, 6.3 or 6.4.

The domain controller will not propagate its administrative RBAC configuration to those slaves, resulting in the slaves (and the servers they manage) granting administrators full administrative privileges.

Comment 1 Jason Shepherd 2016-07-22 06:03:31 UTC
Acknowledgments:

Name: Tomaz Cerar (Red Hat)

Comment 3 Jason Shepherd 2016-07-26 05:17:48 UTC
Knowledge Base article:

https://access.redhat.com/articles/2463641

Comment 5 errata-xmlrpc 2016-09-08 18:20:04 UTC
This issue has been addressed in the following products:



Via RHSA-2016:1841 https://rhn.redhat.com/errata/RHSA-2016-1841.html

Comment 6 errata-xmlrpc 2016-09-08 18:21:09 UTC
This issue has been addressed in the following products:

  Red Hat JBoss Enterprise Application Platform 7.0 for RHEL 7
  Red Hat JBoss Enterprise Application Platform 7.0 for RHEL 6

Via RHSA-2016:1840 https://rhn.redhat.com/errata/RHSA-2016-1840.html

Comment 7 errata-xmlrpc 2016-09-08 18:22:04 UTC
This issue has been addressed in the following products:

  Red Hat JBoss Enterprise Application Platform 7.0 for RHEL 6

Via RHSA-2016:1838 https://rhn.redhat.com/errata/RHSA-2016-1838.html

Comment 8 errata-xmlrpc 2016-09-08 18:41:44 UTC
This issue has been addressed in the following products:

  Red Hat JBoss Enterprise Application Platform 7.0 for RHEL 7

Via RHSA-2016:1839 https://rhn.redhat.com/errata/RHSA-2016-1839.html

Comment 9 errata-xmlrpc 2017-12-13 17:32:12 UTC
This issue has been addressed in the following products:

  Red Hat JBoss Enterprise Application Platform

Via RHSA-2017:3456 https://access.redhat.com/errata/RHSA-2017:3456

Comment 10 errata-xmlrpc 2017-12-13 18:19:31 UTC
This issue has been addressed in the following products:

  Red Hat JBoss Enterprise Application Platform 7.1 for RHEL 6

Via RHSA-2017:3454 https://access.redhat.com/errata/RHSA-2017:3454

Comment 11 errata-xmlrpc 2017-12-13 18:40:54 UTC
This issue has been addressed in the following products:

  Red Hat JBoss Enterprise Application Platform 7.1 for RHEL 7

Via RHSA-2017:3455 https://access.redhat.com/errata/RHSA-2017:3455

Comment 12 errata-xmlrpc 2017-12-13 18:45:56 UTC
This issue has been addressed in the following products:

  Red Hat JBoss Enterprise Application Platform 7.1 for RHEL 7
  Red Hat JBoss Enterprise Application Platform 7.1 for RHEL 6

Via RHSA-2017:3458 https://access.redhat.com/errata/RHSA-2017:3458


Note You need to log in before you can comment on or make changes to this bug.