{"api_version":"1","generated_at":"2026-07-23T21:10:08+00:00","cve":"CVE-2016-2141","urls":{"html":"https://cve.report/CVE-2016-2141","api":"https://cve.report/api/cve/CVE-2016-2141.json","docs":"https://cve.report/api","cve_org":"https://www.cve.org/CVERecord?id=CVE-2016-2141","nvd":"https://nvd.nist.gov/vuln/detail/CVE-2016-2141"},"summary":{"title":"CVE-2016-2141","description":"It was found that JGroups did not require necessary headers for encrypt and auth protocols from new nodes joining the cluster. An attacker could use this flaw to bypass security restrictions, and use this vulnerability to send and receive messages within the cluster, leading to information disclosure, message spoofing, or further possible attacks.","state":"PUBLISHED","assigner":"redhat","published_at":"2016-06-30 16:59:00","updated_at":"2026-05-06 22:30:45"},"problem_types":["NVD-CWE-noinfo","n/a"],"metrics":[{"version":"3.1","source":"nvd@nist.gov","type":"Primary","score":"9.8","severity":"CRITICAL","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H","data":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H","baseScore":9.8,"baseSeverity":"CRITICAL","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"HIGH","integrityImpact":"HIGH","availabilityImpact":"HIGH"}},{"version":"2.0","source":"nvd@nist.gov","type":"Primary","score":"7.5","severity":"","vector":"AV:N/AC:L/Au:N/C:P/I:P/A:P","data":{"version":"2.0","vectorString":"AV:N/AC:L/Au:N/C:P/I:P/A:P","baseScore":7.5,"accessVector":"NETWORK","accessComplexity":"LOW","authentication":"NONE","confidentialityImpact":"PARTIAL","integrityImpact":"PARTIAL","availabilityImpact":"PARTIAL"}}],"references":[{"url":"https://access.redhat.com/errata/RHSA-2016:1432","name":"https://access.redhat.com/errata/RHSA-2016:1432","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":["Vendor Advisory"],"title":"Red Hat Customer Portal","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"https://access.redhat.com/errata/RHSA-2016:1434","name":"https://access.redhat.com/errata/RHSA-2016:1434","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":["Vendor Advisory"],"title":"Red Hat Customer Portal","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"https://rhn.redhat.com/errata/RHSA-2016-1333.html","name":"https://rhn.redhat.com/errata/RHSA-2016-1333.html","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":["Broken Link","Vendor Advisory"],"title":"Red Hat Customer Portal","mime":"text/html","httpstatus":"-1","archivestatus":"200"},{"url":"https://lists.apache.org/thread.html/ra18cac97416abc2958db0b107877c31da28d884fa6e70fd89c87384a%40%3Cdev.geode.apache.org%3E","name":"https://lists.apache.org/thread.html/ra18cac97416abc2958db0b107877c31da28d884fa6e70fd89c87384a%40%3Cdev.geode.apache.org%3E","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"Pony Mail!","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://rhn.redhat.com/errata/RHSA-2016-1435.html","name":"http://rhn.redhat.com/errata/RHSA-2016-1435.html","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":["Vendor Advisory"],"title":"Red Hat Customer Portal","mime":"text/html","httpstatus":"-1","archivestatus":"200"},{"url":"https://access.redhat.com/errata/RHSA-2016:1345","name":"https://access.redhat.com/errata/RHSA-2016:1345","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":["Vendor Advisory"],"title":"Red Hat Customer Portal","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"https://access.redhat.com/errata/RHSA-2016:1347","name":"https://access.redhat.com/errata/RHSA-2016:1347","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":["Vendor Advisory"],"title":"Red Hat Customer Portal","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"https://rhn.redhat.com/errata/RHSA-2016-1329.html","name":"https://rhn.redhat.com/errata/RHSA-2016-1329.html","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":["Broken Link","Vendor Advisory"],"title":"","mime":"","httpstatus":"-1","archivestatus":"404"},{"url":"http://www.securityfocus.com/bid/91481","name":"http://www.securityfocus.com/bid/91481","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":["VDB Entry"],"title":"JGroups CVE-2016-2141 Authorization Bypass Vulnerability","mime":"text/html","httpstatus":"200","archivestatus":"0"},{"url":"https://access.redhat.com/errata/RHSA-2016:1389","name":"https://access.redhat.com/errata/RHSA-2016:1389","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":["Vendor Advisory"],"title":"Red Hat Customer Portal","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://rhn.redhat.com/errata/RHSA-2016-2035.html","name":"http://rhn.redhat.com/errata/RHSA-2016-2035.html","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":["Vendor Advisory"],"title":"Red Hat Customer Portal","mime":"text/html","httpstatus":"-1","archivestatus":"200"},{"url":"https://rhn.redhat.com/errata/RHSA-2016-1330.html","name":"https://rhn.redhat.com/errata/RHSA-2016-1330.html","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":["Vendor Advisory"],"title":"Red Hat Customer Portal","mime":"text/html","httpstatus":"-1","archivestatus":"200"},{"url":"https://rhn.redhat.com/errata/RHSA-2016-1334.html","name":"https://rhn.redhat.com/errata/RHSA-2016-1334.html","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":["Vendor Advisory"],"title":"Red Hat Customer Portal","mime":"text/html","httpstatus":"-1","archivestatus":"200"},{"url":"https://rhn.redhat.com/errata/RHSA-2016-1332.html","name":"https://rhn.redhat.com/errata/RHSA-2016-1332.html","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":["Vendor Advisory"],"title":"Red Hat Customer Portal","mime":"text/html","httpstatus":"-1","archivestatus":"200"},{"url":"http://rhn.redhat.com/errata/RHSA-2016-1439.html","name":"http://rhn.redhat.com/errata/RHSA-2016-1439.html","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":["Vendor Advisory"],"title":"Red Hat Customer Portal","mime":"text/html","httpstatus":"-1","archivestatus":"200"},{"url":"http://www.securitytracker.com/id/1036165","name":"http://www.securitytracker.com/id/1036165","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":["Broken Link","Third Party Advisory","VDB Entry"],"title":"JBoss Authentication Flaw in JGroups Lets Remote Users Bypass Security Restrictions on the Target System - SecurityTracker","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"https://rhn.redhat.com/errata/RHSA-2016-1328.html","name":"https://rhn.redhat.com/errata/RHSA-2016-1328.html","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":["Vendor Advisory"],"title":"Red Hat Customer Portal","mime":"text/html","httpstatus":"-1","archivestatus":"200"},{"url":"https://access.redhat.com/errata/RHSA-2016:1346","name":"https://access.redhat.com/errata/RHSA-2016:1346","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":["Vendor Advisory"],"title":"Red Hat Customer Portal","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"https://access.redhat.com/errata/RHSA-2016:1374","name":"https://access.redhat.com/errata/RHSA-2016:1374","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":["Vendor Advisory"],"title":"Red Hat Customer Portal","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"https://access.redhat.com/errata/RHSA-2016:1376","name":"https://access.redhat.com/errata/RHSA-2016:1376","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":["Vendor Advisory"],"title":"Red Hat Customer Portal - Access to 24x7 support and knowledge","mime":"text/html","httpstatus":"200","archivestatus":"404"},{"url":"https://issues.jboss.org/browse/JGRP-2021","name":"https://issues.jboss.org/browse/JGRP-2021","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":["Issue Tracking","Vendor Advisory"],"title":"[JGRP-2021] ENCRYPT: prevent messages from non-members - JBoss Issue Tracker","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"https://www.oracle.com/technetwork/security-advisory/cpuapr2019-5072813.html","name":"https://www.oracle.com/technetwork/security-advisory/cpuapr2019-5072813.html","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":["Patch","Third Party Advisory"],"title":"Oracle Critical Patch Update Advisory - April 2019","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"https://rhn.redhat.com/errata/RHSA-2016-1331.html","name":"https://rhn.redhat.com/errata/RHSA-2016-1331.html","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":["Broken Link","Vendor Advisory"],"title":"Red Hat Customer Portal","mime":"text/html","httpstatus":"-1","archivestatus":"200"},{"url":"https://access.redhat.com/errata/RHSA-2016:1433","name":"https://access.redhat.com/errata/RHSA-2016:1433","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":["Vendor Advisory"],"title":"Red Hat Customer Portal","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"https://lists.apache.org/thread.html/rb37cc937d4fc026fb56de4b4ec0d054aa4083c1a4edd0d8360c068a0%40%3Cdev.geode.apache.org%3E","name":"https://lists.apache.org/thread.html/rb37cc937d4fc026fb56de4b4ec0d054aa4083c1a4edd0d8360c068a0%40%3Cdev.geode.apache.org%3E","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"Pony Mail!","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"https://lists.apache.org/thread.html/ra18cac97416abc2958db0b107877c31da28d884fa6e70fd89c87384a@%3Cdev.geode.apache.org%3E","name":"MLIST:[geode-dev] 20200407 JGroups vulnerabilty","refsource":"MITRE","tags":[],"title":"Pony Mail!","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"https://lists.apache.org/thread.html/rb37cc937d4fc026fb56de4b4ec0d054aa4083c1a4edd0d8360c068a0@%3Cdev.geode.apache.org%3E","name":"MLIST:[geode-dev] 20200407 Re: JGroups vulnerabilty","refsource":"MITRE","tags":[],"title":"Pony Mail!","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"https://www.cve.org/CVERecord?id=CVE-2016-2141","name":"CVE Program record","refsource":"CVE.ORG","tags":["canonical"]},{"url":"https://nvd.nist.gov/vuln/detail/CVE-2016-2141","name":"NVD vulnerability detail","refsource":"NVD","tags":["canonical","analysis"]}],"affected":[{"source":"CNA","vendor":"n/a","product":"n/a","version":"affected n/a","platforms":[]}],"timeline":[],"solutions":[],"workarounds":[],"exploits":[],"credits":[],"nvd_cpes":[{"cve_year":"2016","cve_id":"2141","vulnerable":"0","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"o","cpe4":"redhat","cpe5":"enterprise_linux","cpe6":"5.0","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"},{"cve_year":"2016","cve_id":"2141","vulnerable":"0","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"o","cpe4":"redhat","cpe5":"enterprise_linux","cpe6":"6.0","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"},{"cve_year":"2016","cve_id":"2141","vulnerable":"0","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"o","cpe4":"redhat","cpe5":"enterprise_linux","cpe6":"7.0","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"},{"cve_year":"2016","cve_id":"2141","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"redhat","cpe5":"jboss_enterprise_application_platform","cpe6":"5.2","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"},{"cve_year":"2016","cve_id":"2141","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"redhat","cpe5":"jboss_enterprise_application_platform","cpe6":"6.4","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"},{"cve_year":"2016","cve_id":"2141","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"redhat","cpe5":"jboss_enterprise_application_platform","cpe6":"7.0","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"},{"cve_year":"2016","cve_id":"2141","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"redhat","cpe5":"jgroups","cpe6":"*","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"}],"vendor_comments":[],"enrichments":{"kev":null,"epss":null,"legacy_qids":[]},"source_records":{"cve_program":{"containers":{"adp":[{"providerMetadata":{"dateUpdated":"2024-08-05T23:17:50.610Z","orgId":"af854a3a-2127-422b-91ae-364da2661108","shortName":"CVE"},"references":[{"name":"RHSA-2016:1347","tags":["vendor-advisory","x_transferred"],"url":"https://access.redhat.com/errata/RHSA-2016:1347"},{"name":"RHSA-2016:2035","tags":["vendor-advisory","x_transferred"],"url":"http://rhn.redhat.com/errata/RHSA-2016-2035.html"},{"name":"RHSA-2016:1389","tags":["vendor-advisory","x_transferred"],"url":"https://access.redhat.com/errata/RHSA-2016:1389"},{"name":"RHSA-2016:1345","tags":["vendor-advisory","x_transferred"],"url":"https://access.redhat.com/errata/RHSA-2016:1345"},{"name":"RHSA-2016:1376","tags":["vendor-advisory","x_transferred"],"url":"https://access.redhat.com/errata/RHSA-2016:1376"},{"name":"RHSA-2016:1330","tags":["vendor-advisory","x_transferred"],"url":"https://rhn.redhat.com/errata/RHSA-2016-1330.html"},{"name":"RHSA-2016:1439","tags":["vendor-advisory","x_transferred"],"url":"http://rhn.redhat.com/errata/RHSA-2016-1439.html"},{"name":"RHSA-2016:1331","tags":["vendor-advisory","x_transferred"],"url":"https://rhn.redhat.com/errata/RHSA-2016-1331.html"},{"name":"91481","tags":["vdb-entry","x_transferred"],"url":"http://www.securityfocus.com/bid/91481"},{"name":"RHSA-2016:1434","tags":["vendor-advisory","x_transferred"],"url":"https://access.redhat.com/errata/RHSA-2016:1434"},{"name":"RHSA-2016:1328","tags":["vendor-advisory","x_transferred"],"url":"https://rhn.redhat.com/errata/RHSA-2016-1328.html"},{"name":"RHSA-2016:1433","tags":["vendor-advisory","x_transferred"],"url":"https://access.redhat.com/errata/RHSA-2016:1433"},{"tags":["x_transferred"],"url":"https://issues.jboss.org/browse/JGRP-2021"},{"name":"RHSA-2016:1374","tags":["vendor-advisory","x_transferred"],"url":"https://access.redhat.com/errata/RHSA-2016:1374"},{"name":"RHSA-2016:1432","tags":["vendor-advisory","x_transferred"],"url":"https://access.redhat.com/errata/RHSA-2016:1432"},{"name":"RHSA-2016:1346","tags":["vendor-advisory","x_transferred"],"url":"https://access.redhat.com/errata/RHSA-2016:1346"},{"name":"RHSA-2016:1334","tags":["vendor-advisory","x_transferred"],"url":"https://rhn.redhat.com/errata/RHSA-2016-1334.html"},{"name":"RHSA-2016:1333","tags":["vendor-advisory","x_transferred"],"url":"https://rhn.redhat.com/errata/RHSA-2016-1333.html"},{"name":"RHSA-2016:1329","tags":["vendor-advisory","x_transferred"],"url":"https://rhn.redhat.com/errata/RHSA-2016-1329.html"},{"name":"RHSA-2016:1332","tags":["vendor-advisory","x_transferred"],"url":"https://rhn.redhat.com/errata/RHSA-2016-1332.html"},{"name":"RHSA-2016:1435","tags":["vendor-advisory","x_transferred"],"url":"http://rhn.redhat.com/errata/RHSA-2016-1435.html"},{"name":"1036165","tags":["vdb-entry","x_transferred"],"url":"http://www.securitytracker.com/id/1036165"},{"tags":["x_transferred"],"url":"https://www.oracle.com/technetwork/security-advisory/cpuapr2019-5072813.html"},{"name":"[geode-dev] 20200407 JGroups vulnerabilty","tags":["mailing-list","x_transferred"],"url":"https://lists.apache.org/thread.html/ra18cac97416abc2958db0b107877c31da28d884fa6e70fd89c87384a%40%3Cdev.geode.apache.org%3E"},{"name":"[geode-dev] 20200407 Re: JGroups vulnerabilty","tags":["mailing-list","x_transferred"],"url":"https://lists.apache.org/thread.html/rb37cc937d4fc026fb56de4b4ec0d054aa4083c1a4edd0d8360c068a0%40%3Cdev.geode.apache.org%3E"}],"title":"CVE Program Container"}],"cna":{"affected":[{"product":"n/a","vendor":"n/a","versions":[{"status":"affected","version":"n/a"}]}],"datePublic":"2016-06-23T00:00:00.000Z","descriptions":[{"lang":"en","value":"It was found that JGroups did not require necessary headers for encrypt and auth protocols from new nodes joining the cluster. An attacker could use this flaw to bypass security restrictions, and use this vulnerability to send and receive messages within the cluster, leading to information disclosure, message spoofing, or further possible attacks."}],"problemTypes":[{"descriptions":[{"description":"n/a","lang":"en","type":"text"}]}],"providerMetadata":{"dateUpdated":"2023-04-26T00:00:00.000Z","orgId":"53f830b8-0a3f-465b-8143-3b8a9948e749","shortName":"redhat"},"references":[{"name":"RHSA-2016:1347","tags":["vendor-advisory"],"url":"https://access.redhat.com/errata/RHSA-2016:1347"},{"name":"RHSA-2016:2035","tags":["vendor-advisory"],"url":"http://rhn.redhat.com/errata/RHSA-2016-2035.html"},{"name":"RHSA-2016:1389","tags":["vendor-advisory"],"url":"https://access.redhat.com/errata/RHSA-2016:1389"},{"name":"RHSA-2016:1345","tags":["vendor-advisory"],"url":"https://access.redhat.com/errata/RHSA-2016:1345"},{"name":"RHSA-2016:1376","tags":["vendor-advisory"],"url":"https://access.redhat.com/errata/RHSA-2016:1376"},{"name":"RHSA-2016:1330","tags":["vendor-advisory"],"url":"https://rhn.redhat.com/errata/RHSA-2016-1330.html"},{"name":"RHSA-2016:1439","tags":["vendor-advisory"],"url":"http://rhn.redhat.com/errata/RHSA-2016-1439.html"},{"name":"RHSA-2016:1331","tags":["vendor-advisory"],"url":"https://rhn.redhat.com/errata/RHSA-2016-1331.html"},{"name":"91481","tags":["vdb-entry"],"url":"http://www.securityfocus.com/bid/91481"},{"name":"RHSA-2016:1434","tags":["vendor-advisory"],"url":"https://access.redhat.com/errata/RHSA-2016:1434"},{"name":"RHSA-2016:1328","tags":["vendor-advisory"],"url":"https://rhn.redhat.com/errata/RHSA-2016-1328.html"},{"name":"RHSA-2016:1433","tags":["vendor-advisory"],"url":"https://access.redhat.com/errata/RHSA-2016:1433"},{"url":"https://issues.jboss.org/browse/JGRP-2021"},{"name":"RHSA-2016:1374","tags":["vendor-advisory"],"url":"https://access.redhat.com/errata/RHSA-2016:1374"},{"name":"RHSA-2016:1432","tags":["vendor-advisory"],"url":"https://access.redhat.com/errata/RHSA-2016:1432"},{"name":"RHSA-2016:1346","tags":["vendor-advisory"],"url":"https://access.redhat.com/errata/RHSA-2016:1346"},{"name":"RHSA-2016:1334","tags":["vendor-advisory"],"url":"https://rhn.redhat.com/errata/RHSA-2016-1334.html"},{"name":"RHSA-2016:1333","tags":["vendor-advisory"],"url":"https://rhn.redhat.com/errata/RHSA-2016-1333.html"},{"name":"RHSA-2016:1329","tags":["vendor-advisory"],"url":"https://rhn.redhat.com/errata/RHSA-2016-1329.html"},{"name":"RHSA-2016:1332","tags":["vendor-advisory"],"url":"https://rhn.redhat.com/errata/RHSA-2016-1332.html"},{"name":"RHSA-2016:1435","tags":["vendor-advisory"],"url":"http://rhn.redhat.com/errata/RHSA-2016-1435.html"},{"name":"1036165","tags":["vdb-entry"],"url":"http://www.securitytracker.com/id/1036165"},{"url":"https://www.oracle.com/technetwork/security-advisory/cpuapr2019-5072813.html"},{"name":"[geode-dev] 20200407 JGroups vulnerabilty","tags":["mailing-list"],"url":"https://lists.apache.org/thread.html/ra18cac97416abc2958db0b107877c31da28d884fa6e70fd89c87384a%40%3Cdev.geode.apache.org%3E"},{"name":"[geode-dev] 20200407 Re: JGroups vulnerabilty","tags":["mailing-list"],"url":"https://lists.apache.org/thread.html/rb37cc937d4fc026fb56de4b4ec0d054aa4083c1a4edd0d8360c068a0%40%3Cdev.geode.apache.org%3E"}]}},"cveMetadata":{"assignerOrgId":"53f830b8-0a3f-465b-8143-3b8a9948e749","assignerShortName":"redhat","cveId":"CVE-2016-2141","datePublished":"2016-06-30T00:00:00.000Z","dateReserved":"2016-01-29T00:00:00.000Z","dateUpdated":"2024-08-05T23:17:50.610Z","state":"PUBLISHED"},"dataType":"CVE_RECORD","dataVersion":"5.1"},"nvd":{"publishedDate":"2016-06-30 16:59:00","lastModifiedDate":"2026-05-06 22:30:45","problem_types":["NVD-CWE-noinfo","n/a"],"metrics":{"cvssMetricV31":[{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H","baseScore":9.8,"baseSeverity":"CRITICAL","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"HIGH","integrityImpact":"HIGH","availabilityImpact":"HIGH"},"exploitabilityScore":3.9,"impactScore":5.9}],"cvssMetricV2":[{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"2.0","vectorString":"AV:N/AC:L/Au:N/C:P/I:P/A:P","baseScore":7.5,"accessVector":"NETWORK","accessComplexity":"LOW","authentication":"NONE","confidentialityImpact":"PARTIAL","integrityImpact":"PARTIAL","availabilityImpact":"PARTIAL"},"baseSeverity":"HIGH","exploitabilityScore":10,"impactScore":6.4,"acInsufInfo":false,"obtainAllPrivilege":false,"obtainUserPrivilege":false,"obtainOtherPrivilege":false,"userInteractionRequired":false}]},"configurations":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:redhat:jgroups:*:*:*:*:*:*:*:*","versionEndExcluding":"4.0","matchCriteriaId":"EEEE3873-17F7-4E5D-9C19-1C1BE698A17E"}]}]},{"operator":"AND","nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:redhat:jboss_enterprise_application_platform:5.2:*:*:*:*:*:*:*","matchCriteriaId":"93F14D0A-4350-4141-B4C4-FBEBAAA4828D"},{"vulnerable":true,"criteria":"cpe:2.3:a:redhat:jboss_enterprise_application_platform:6.4:*:*:*:*:*:*:*","matchCriteriaId":"E2E0AFF9-F664-4D46-AEF4-07C725CC5448"},{"vulnerable":true,"criteria":"cpe:2.3:a:redhat:jboss_enterprise_application_platform:7.0:*:*:*:*:*:*:*","matchCriteriaId":"88BF3B2C-B121-483A-AEF2-8082F6DA5310"}]},{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":false,"criteria":"cpe:2.3:o:redhat:enterprise_linux:5.0:*:*:*:*:*:*:*","matchCriteriaId":"1D8B549B-E57B-4DFE-8A13-CAB06B5356B3"},{"vulnerable":false,"criteria":"cpe:2.3:o:redhat:enterprise_linux:6.0:*:*:*:*:*:*:*","matchCriteriaId":"2F6AB192-9D7D-4A9A-8995-E53A9DE9EAFC"},{"vulnerable":false,"criteria":"cpe:2.3:o:redhat:enterprise_linux:7.0:*:*:*:*:*:*:*","matchCriteriaId":"142AD0DD-4CF3-4D74-9442-459CE3347E3A"}]}]}]},"legacy_mitre":{"record":{"CveYear":"2016","CveId":"2141","Ordinal":"1","Title":"CVE-2016-2141","CVE":"CVE-2016-2141","Year":"2016"},"notes":[{"CveYear":"2016","CveId":"2141","Ordinal":"1","NoteData":"It was found that JGroups did not require necessary headers for encrypt and auth protocols from new nodes joining the cluster. An attacker could use this flaw to bypass security restrictions, and use this vulnerability to send and receive messages within the cluster, leading to information disclosure, message spoofing, or further possible attacks.","Type":"Description","Title":"CVE-2016-2141"},{"CveYear":"2016","CveId":"2141","Ordinal":"2","NoteData":"2016-06-30","Type":"Other","Title":"Published"},{"CveYear":"2016","CveId":"2141","Ordinal":"3","NoteData":"2020-04-07","Type":"Other","Title":"Modified"}]}}}