CVE-2016-7066: Red Hat JBoss Enterprise Application Platform

High severity, CVSS 7.8. EPSS: 0.3% chance of exploitation in the next 30 days.

It was found that the improper default permissions on /tmp/auth directory in JBoss Enterprise Application Platform before 7.1.0 can allow any local user to connect to CLI and allow the user to execute any arbitrary operations.

Affected products

  • Red Hat JBoss Enterprise Application Platform: before 7.1.0 (fixed in 7.1.0)

Published 2018-09-11. Last modified 2026-06-17.