PT-2020-9624 · Red Hat · Jboss Eap

Published

2020-01-23

·

Updated

2022-11-08

·

CVE-2019-14885

CVSS v3.1

5.4

Medium

VectorAV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:N
Name of the Vulnerable Software and Affected Versions JBoss EAP versions prior to 7.2.6.GA
Description A flaw in the JBoss EAP Vault system can reveal confidential information of the system property's security attribute value in the JBoss EAP log file when executing a JBoss CLI 'reload' command, potentially leading to the exposure of confidential information.
Recommendations For versions prior to 7.2.6.GA, update to version 7.2.6.GA or later to resolve the issue.

Fix

Insertion into Log File

Weakness Enumeration

Related Identifiers

CVE-2019-14885
RHSA-2020:0159
RHSA-2020:0160
RHSA-2020:0161
RHSA-2020:2169
RHSA-2020:2779
RHSA-2020:2780
RHSA-2020:2781

Affected Products

Jboss Eap