CVE-2016-5406: Red Hat JBoss Enterprise Application Platform
High severity, CVSS 8.8. EPSS: 2.9% chance of exploitation in the next 30 days.
The domain controller in Red Hat JBoss Enterprise Application Platform (EAP) 7.x before 7.0.2 allows remote authenticated users to gain privileges by leveraging failure to propagate administrative RBAC configuration to all slaves.
Affected products
- Red Hat JBoss Enterprise Application Platform: up to and including 7.0.1
Published 2016-09-26. Last modified 2026-06-17.