Vulnerability Description
It was discovered that the jboss init script as used in Red Hat JBoss Enterprise Application Platform 7.0.7.GA performed unsafe file handling which could result in local privilege escalation. This issue is a result of an incomplete fix for CVE-2016-8656.
CVSS Score
HIGH
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Redhat | Jboss Enterprise Application Platform | 7.0 |
| Redhat | Enterprise Linux | 6.0 |
Related Weaknesses (CWE)
References
- http://www.securityfocus.com/bid/102407Third Party AdvisoryVDB Entry
- https://access.redhat.com/errata/RHSA-2018:0002PatchVendor Advisory
- https://access.redhat.com/errata/RHSA-2018:0003PatchVendor Advisory
- https://access.redhat.com/errata/RHSA-2018:0004PatchVendor Advisory
- https://access.redhat.com/errata/RHSA-2018:0005PatchVendor Advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=CVE-2017-12189Issue TrackingThird Party Advisory
- http://www.securityfocus.com/bid/102407Third Party AdvisoryVDB Entry
- https://access.redhat.com/errata/RHSA-2018:0002PatchVendor Advisory
- https://access.redhat.com/errata/RHSA-2018:0003PatchVendor Advisory
- https://access.redhat.com/errata/RHSA-2018:0004PatchVendor Advisory
- https://access.redhat.com/errata/RHSA-2018:0005PatchVendor Advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=CVE-2017-12189Issue TrackingThird Party Advisory
FAQ
What is CVE-2017-12189?
CVE-2017-12189 is a vulnerability with a CVSS score of 7.8 (HIGH). It was discovered that the jboss init script as used in Red Hat JBoss Enterprise Application Platform 7.0.7.GA performed unsafe file handling which could result in local privilege escalation. This iss...
How severe is CVE-2017-12189?
CVE-2017-12189 has been rated HIGH with a CVSS base score of 7.8/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2017-12189?
Check the references section above for vendor advisories and patch information. Affected products include: Redhat Jboss Enterprise Application Platform, Redhat Enterprise Linux.