Jboss EAP Permissions Privileges and Access Controls Vulnerability - CVE-2016-2141 - Vulnerability Database

Jboss EAP Permissions Privileges and Access Controls Vulnerability - CVE-2016-2141

Critical
Reference: CVE-2016-2141
Title: Jboss EAP Permissions Privileges and Access Controls Vulnerability
Overview:

JGroups before 4.0 does not require the proper headers for the ENCRYPT and AUTH protocols from nodes joining the cluster which allows remote attackers to bypass security restrictions and send and receive messages within the cluster via unspecified vectors.