PT-2014-2269 · Red Hat · Red Hat Jboss Enterprise Application Platform
Aleksandar Kostadinov
·
Publicado
2014-02-02
·
Atualizado
2017-08-29
·
CVE-2012-3427
CVSS v2.0
2.1
Baixa
| Vetor | AV:L/AC:L/Au:N/C:P/I:N/A:N |
Name of the Vulnerable Software and Affected Versions
JBoss Enterprise Application Platform (EAP) version 5.1.2
Description
The issue allows local users to read sensitive information, including Amazon Web Services (AWS) credentials, by accessing files in the /var/cache/jboss-ec2-eap/ directory due to the use of 755 permissions.
Recommendations
For JBoss Enterprise Application Platform (EAP) version 5.1.2, consider changing the permissions of the /var/cache/jboss-ec2-eap/ directory to prevent local users from reading sensitive information.
Correção
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾
Enumeração de Fraquezas
Identificadores relacionados
Produtos afetados
Red Hat Jboss Enterprise Application Platform