CVE-2016-8657: Red Hat JBoss Enterprise Application Platform

High severity, CVSS 7.8. EPSS: 0.4% chance of exploitation in the next 30 days.

It was discovered that EAP packages in certain versions of Red Hat Enterprise Linux use incorrect permissions for /etc/sysconfig/jbossas configuration files. The file is writable to jboss group (root:jboss, 664). On systems using classic /etc/init.d init scripts (i.e. on Red Hat Enterprise Linux 6 and earlier), the file is sourced by the jboss init script and its content executed with root privileges when jboss service is started, stopped, or restarted.

Affected products

  • Red Hat JBoss Enterprise Application Platform: version 6.0.0 only; version 6.4.0 only; version 5.0.0 only

Published 2018-07-31. Last modified 2026-06-17.