PT-2017-6528 · Red Hat · Red Hat Jboss Enterprise Application Platform

Vasyl Kaigorodov

·

Published

2017-09-19

·

Updated

2017-10-04

·

CVE-2015-1849

CVSS v2.0

4.3

Medium

VectorAV:N/AC:M/Au:N/C:P/I:N/A:N
Name of the Vulnerable Software and Affected Versions Red Hat JBoss Enterprise Application Platform (EAP) versions prior to 6.4.1
Description The issue allows attackers to obtain sensitive information via vectors involving logging the LDAP bind credential password when TRACE logging is enabled. This affects the AdvancedLdapLoginModule in Red Hat JBoss Enterprise Application Platform (EAP).
Recommendations For versions prior to 6.4.1, update to version 6.4.1 or later to resolve the issue. As a temporary workaround, consider disabling TRACE logging to minimize the risk of exploitation. Restrict access to the AdvancedLdapLoginModule to minimize the risk of sensitive information disclosure.

Exploit

Fix

Information Disclosure

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2015-1849

Affected Products

Red Hat Jboss Enterprise Application Platform