PT-2014-2269 · Red Hat · Red Hat Jboss Enterprise Application Platform

Aleksandar Kostadinov

·

Published

2014-02-02

·

Updated

2017-08-29

·

CVE-2012-3427

CVSS v2.0

2.1

Low

VectorAV:L/AC:L/Au:N/C:P/I:N/A:N
Name of the Vulnerable Software and Affected Versions JBoss Enterprise Application Platform (EAP) version 5.1.2
Description The issue allows local users to read sensitive information, including Amazon Web Services (AWS) credentials, by accessing files in the /var/cache/jboss-ec2-eap/ directory due to the use of 755 permissions.
Recommendations For JBoss Enterprise Application Platform (EAP) version 5.1.2, consider changing the permissions of the /var/cache/jboss-ec2-eap/ directory to prevent local users from reading sensitive information.

Fix

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2012-3427
RHSA-2012:1376

Affected Products

Red Hat Jboss Enterprise Application Platform