Privilege escalation in Oracle GlassFish Server - CVE-2016-5519

 

Privilege escalation in Oracle GlassFish Server - CVE-2016-5519

Published: October 19, 2016 / Updated: January 4, 2017


Vulnerability identifier: #VU1045
CSH Severity: Low
CVSS v4: 8.7 [CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
CVE-ID: CVE-2016-5519
CWE-ID: CWE-20
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote authenticated user to gain elevated orivileges on the target system.
The weakness is due to improper processing of crafted packets during the enrollment operation. Flaw in the Oracle GlassFish Server Java Server Faces component lets attacker to increase his privileges.
Successful exploitation of the vulnerability results in privilege escalation on the vulnerable system.

Affected software

Oracle GlassFish Server
openEuler
kernel
bpftool
bpftool-debuginfo
kernel-debuginfo
kernel-debugsource
kernel-devel
kernel-source
kernel-tools
kernel-tools-debuginfo
kernel-tools-devel
perf
perf-debuginfo
python2-perf
python2-perf-debuginfo
python3-perf
python3-perf-debuginfo

How to mitigate CVE-2016-5519


kernel - update to 4.19.90-2407.3.0.0285
bpftool - update to 4.19.90-2407.3.0.0285
bpftool-debuginfo - update to 4.19.90-2407.3.0.0285
kernel-debuginfo - update to 4.19.90-2407.3.0.0285
kernel-debugsource - update to 4.19.90-2407.3.0.0285
kernel-devel - update to 4.19.90-2407.3.0.0285
kernel-source - update to 4.19.90-2407.3.0.0285
kernel-tools - update to 4.19.90-2407.3.0.0285
kernel-tools-debuginfo - update to 4.19.90-2407.3.0.0285
kernel-tools-devel - update to 4.19.90-2407.3.0.0285
perf - update to 4.19.90-2407.3.0.0285
perf-debuginfo - update to 4.19.90-2407.3.0.0285
python2-perf - update to 4.19.90-2407.3.0.0285
python2-perf-debuginfo - update to 4.19.90-2407.3.0.0285
python3-perf - update to 4.19.90-2407.3.0.0285
python3-perf-debuginfo - update to 4.19.90-2407.3.0.0285

External References

Related Security Bulletins