VYPR
Medium severity4.3OSV Advisory· Published May 11, 2018· Updated Jun 17, 2026

CVE-2016-8627

CVE-2016-8627

Description

admin-cli before versions 3.0.0.alpha25, 2.2.1.cr2 is vulnerable to an EAP feature to download server log files that allows logs to be available via GET requests making them vulnerable to cross-origin attacks. An attacker could trigger the user's browser to request the log files consuming enough resources that normal server functioning could be impaired.

AI Insight

LLM-synthesized narrative grounded in this CVE's description and references.

Affected products

6
  • Range: 1.0-alpha-1, 1.0-alpha-1-12062013, 1.0-alpha-2, …
  • cpe:2.3:a:redhat:jboss_enterprise_application_platform:6.4.0:*:*:*:*:*:*:*+ 2 more
    • cpe:2.3:a:redhat:jboss_enterprise_application_platform:6.4.0:*:*:*:*:*:*:*
    • cpe:2.3:a:redhat:jboss_enterprise_application_platform:7.0.0:*:*:*:*:*:*:*
    • cpe:2.3:a:redhat:jboss_enterprise_application_platform:7.1.0:*:*:*:*:*:*:*
  • cpe:2.3:a:redhat:keycloak:-:*:*:*:*:*:*:*
  • Range: <3.0.0.alpha25, <2.2.1.cr2

Patches

Vulnerability mechanics

References

16

News mentions

0

No linked articles in our index yet.