Vulnerability Details CVE-2016-5422
The web console in Red Hat JBoss Operations Network (JON) before 3.3.7 does not properly authorize requests to add users with the super user role, which allows remote authenticated users to gain admin privileges via a crafted POST request.
Exploit prediction scoring system (EPSS) score
EPSS Score 0.007
EPSS Ranking 70.4%
CVSS Severity
CVSS v3 Score 8.8
CVSS v2 Score 6.5
Products affected by CVE-2016-5422
-
cpe:2.3:a:redhat:jboss_operations_network:1.0.0
-
cpe:2.3:a:redhat:jboss_operations_network:2.0.0
-
cpe:2.3:a:redhat:jboss_operations_network:2.0.1
-
cpe:2.3:a:redhat:jboss_operations_network:2.1.0
-
cpe:2.3:a:redhat:jboss_operations_network:2.1.2
-
cpe:2.3:a:redhat:jboss_operations_network:2.2
-
cpe:2.3:a:redhat:jboss_operations_network:2.3
-
cpe:2.3:a:redhat:jboss_operations_network:2.3.1
-
cpe:2.3:a:redhat:jboss_operations_network:2.4
-
cpe:2.3:a:redhat:jboss_operations_network:2.4.1
-
cpe:2.3:a:redhat:jboss_operations_network:2.4.2
-
cpe:2.3:a:redhat:jboss_operations_network:3.0
-
cpe:2.3:a:redhat:jboss_operations_network:3.0.1
-
cpe:2.3:a:redhat:jboss_operations_network:3.1
-
cpe:2.3:a:redhat:jboss_operations_network:3.1.1
-
cpe:2.3:a:redhat:jboss_operations_network:3.1.2
-
cpe:2.3:a:redhat:jboss_operations_network:3.1.4
-
cpe:2.3:a:redhat:jboss_operations_network:3.2.0
-
cpe:2.3:a:redhat:jboss_operations_network:3.2.1
-
cpe:2.3:a:redhat:jboss_operations_network:3.2.2
-
cpe:2.3:a:redhat:jboss_operations_network:3.2.3
-
cpe:2.3:a:redhat:jboss_operations_network:3.2.4
-
cpe:2.3:a:redhat:jboss_operations_network:3.3.1
-
cpe:2.3:a:redhat:jboss_operations_network:3.3.2
-
cpe:2.3:a:redhat:jboss_operations_network:3.3.3
-
cpe:2.3:a:redhat:jboss_operations_network:3.3.4
-
cpe:2.3:a:redhat:jboss_operations_network:3.3.5
-
cpe:2.3:a:redhat:jboss_operations_network:3.3.6