CVE-2016-8627: Red Hat JBoss Enterprise Application Platform
Medium severity, CVSS 6.5. EPSS: 2.6% chance of exploitation in the next 30 days.
admin-cli before versions 3.0.0.alpha25, 2.2.1.cr2 is vulnerable to an EAP feature to download server log files that allows logs to be available via GET requests making them vulnerable to cross-origin attacks. An attacker could trigger the user's browser to request the log files consuming enough resources that normal server functioning could be impaired.
Affected products
- Red Hat JBoss Enterprise Application Platform: version 6.4.0 only; version 7.0.0 only; version 7.1.0 only
- Red Hat Keycloak: affected versions not specified
Published 2018-05-11. Last modified 2026-06-17.