PT-2013-4940 · Red Hat · Red Hat Jboss Operations Network

Arun Babu Neelicattu

+1

·

Publicado

2013-10-24

·

Atualizado

2013-10-25

·

CVE-2013-4293

CVSS v2.0

2.1

Baixa

VetorAV:L/AC:L/Au:N/C:P/I:N/A:N
Name of the Vulnerable Software and Affected Versions Red Hat JBoss Operations Network (JON) version 3.1.2
Description The issue allows local users to obtain sensitive information by reading the log files, as the server logs passwords in plaintext.
Recommendations For Red Hat JBoss Operations Network (JON) version 3.1.2, consider restricting access to the log files to minimize the risk of exploitation. As a temporary workaround, review and modify the logging configuration to avoid storing sensitive information, such as passwords, in plaintext.

Correção

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

CVE-2013-4293

Produtos afetados

Red Hat Jboss Operations Network