PT-2014-2269 · Red Hat · Red Hat Jboss Enterprise Application Platform

Aleksandar Kostadinov

·

Publicado

2014-02-02

·

Atualizado

2017-08-29

·

CVE-2012-3427

CVSS v2.0

2.1

Baixa

VetorAV:L/AC:L/Au:N/C:P/I:N/A:N
Name of the Vulnerable Software and Affected Versions JBoss Enterprise Application Platform (EAP) version 5.1.2
Description The issue allows local users to read sensitive information, including Amazon Web Services (AWS) credentials, by accessing files in the /var/cache/jboss-ec2-eap/ directory due to the use of 755 permissions.
Recommendations For JBoss Enterprise Application Platform (EAP) version 5.1.2, consider changing the permissions of the /var/cache/jboss-ec2-eap/ directory to prevent local users from reading sensitive information.

Correção

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

CVE-2012-3427
RHSA-2012:1376

Produtos afetados

Red Hat Jboss Enterprise Application Platform