Description
It was found that the improper default permissions on /tmp/auth directory in JBoss Enterprise Application Platform before 7.1.0 can allow any local user to connect to CLI and allow the user to execute any arbitrary operations.
Remediation
References
Related Vulnerabilities
WordPress Plugin Animal Captcha Cross-Site Scripting (1.6.2)
WordPress Plugin Countdown and CountUp, WooCommerce Sales Timer Cross-Site Request Forgery (1.5.7)
Liferay DXP Incorrect Authorization Vulnerability (CVE-2025-3586)
WordPress Cross-Site Request Forgery (CSRF) Vulnerability (CVE-2020-28040)