Red Hat Bugzilla – Bug 1401661
CVE-2016-7066 admin-cli: Any local users can connect to jboss-cli
Last modified: 2018-10-19 17:38:51 EDT
The improper default permissions on /tmp/auth directory can allow any local user to connect to CLI and allow arbitary operations.
This issue has been addressed in the following products: Red Hat JBoss Enterprise Application Platform Via RHSA-2017:3456 https://access.redhat.com/errata/RHSA-2017:3456