CVE-2016-8657
Last modified
CVE-2016-8657 is a vulnerability of currently unknown severity. It was discovered that EAP packages in certain versions of Red Hat Enterprise Linux use incorrect permissions for /etc/sysconfig/jbossas configuration files. The file is writable to jboss group (root:jboss, 664). EPSS estimates a 0.42% chance of exploitation in the next 30 days.
Description
It was discovered that EAP packages in certain versions of Red Hat Enterprise Linux use incorrect permissions for /etc/sysconfig/jbossas configuration files. The file is writable to jboss group (root:jboss, 664). On systems using classic /etc/init.d init scripts (i.e. on Red Hat Enterprise Linux 6 and earlier), the file is sourced by the jboss init script and its content executed with root privileges when jboss service is started, stopped, or restarted.
Metrics
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Redhat | Jboss Enterprise Application Platform | 6.0.0 |
| Redhat | Jboss Enterprise Application Platform | 6.4.0 |
| Redhat | Jboss Enterprise Application Platform | 5.0.0 |
References
- http://rhn.redhat.com/errata/RHSA-2017-0826.htmlVendor Advisory
- http://rhn.redhat.com/errata/RHSA-2017-0827.htmlVendor Advisory
- http://rhn.redhat.com/errata/RHSA-2017-0828.htmlVendor Advisory
- http://rhn.redhat.com/errata/RHSA-2017-0829.htmlVendor Advisory
- http://www.securityfocus.com/bid/96896Third Party Advisory, VDB Entry
- https://access.redhat.com/errata/RHSA-2018:1609Vendor Advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=CVE-2016-8657Issue Tracking, Vendor Advisory
- http://rhn.redhat.com/errata/RHSA-2017-0826.htmlVendor Advisory
- http://rhn.redhat.com/errata/RHSA-2017-0827.htmlVendor Advisory
- http://rhn.redhat.com/errata/RHSA-2017-0828.htmlVendor Advisory
- http://rhn.redhat.com/errata/RHSA-2017-0829.htmlVendor Advisory
- http://www.securityfocus.com/bid/96896Third Party Advisory, VDB Entry
- https://access.redhat.com/errata/RHSA-2018:1609Vendor Advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=CVE-2016-8657Issue Tracking, Vendor Advisory
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2016-8657?
How severe is CVE-2016-8657?
How do I fix CVE-2016-8657?
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2016
- CVE-2016-8651An input validation flaw was found in the way OpenShift 3 ha…3.1
- CVE-2016-8652The auth component in Dovecot before 2.2.27, when auth-polic…
- CVE-2016-8653It was found that the JMX endpoint of Red Hat JBoss Fuse 6, …5.3
- CVE-2016-8654A heap-buffer overflow vulnerability was found in QMFB code …7.8
- CVE-2016-8655Race condition in net/packet/af_packet.c in the Linux kernel…7.8
- CVE-2016-8656Jboss jbossas before versions 5.2.0-23, 6.4.13, 7.0.5 is vul…7
- CVE-2016-8658Stack-based buffer overflow in the brcmf_cfg80211_start_ap f…
- CVE-2016-8659Bubblewrap before 0.1.3 sets the PR_SET_DUMPABLE flag, which…
- CVE-2016-8660The XFS subsystem in the Linux kernel through 4.8.2 allows l…
- CVE-2016-8661Little Snitch version 3.0 through 3.6.1 suffer from a buffer…
- CVE-2016-8662Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultID…
- CVE-2016-8663Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultID…
Are you affected by CVE-2016-8657?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
