PT-2014-2269 · Red Hat · Red Hat Jboss Enterprise Application Platform
Aleksandar Kostadinov
·
Published
2014-02-02
·
Updated
2017-08-29
·
CVE-2012-3427
CVSS v2.0
2.1
Low
| Vector | AV:L/AC:L/Au:N/C:P/I:N/A:N |
Name of the Vulnerable Software and Affected Versions
JBoss Enterprise Application Platform (EAP) version 5.1.2
Description
The issue allows local users to read sensitive information, including Amazon Web Services (AWS) credentials, by accessing files in the /var/cache/jboss-ec2-eap/ directory due to the use of 755 permissions.
Recommendations
For JBoss Enterprise Application Platform (EAP) version 5.1.2, consider changing the permissions of the /var/cache/jboss-ec2-eap/ directory to prevent local users from reading sensitive information.
Fix
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Red Hat Jboss Enterprise Application Platform