World Readable User Role Mapping Vulnerability in EAP 7 by Red Hat
CVE-2017-12167
5.5MEDIUM
Key Information:
What is CVE-2017-12167?
In EAP 7, prior to version 7.0.9, a security flaw was identified where property-based configuration files for both management and application realms were set with world-readable permissions. This exposure allowed all authenticated users to access sensitive information regarding user-role mappings, potentially leading to unauthorized privilege escalation and compromising user data security.
Affected Version(s)
EAP-7 7.0.9