CVE-2016-7061: Red Hat JBoss Enterprise Application Platform
Medium severity, CVSS 6.5. EPSS: 1.8% chance of exploitation in the next 30 days.
An information disclosure vulnerability was found in JBoss Enterprise Application Platform before 7.0.4. It was discovered that when configuring RBAC and marking information as sensitive, users with a Monitor role are able to view the sensitive information.
Affected products
- Red Hat JBoss Enterprise Application Platform: before 7.0.4 (fixed in 7.0.4)
Published 2018-09-10. Last modified 2026-06-17.