CVE Vulnerabilities

CVE-2014-0058

Published: Feb 26, 2014 | Modified: Jan 07, 2017
CVSS 3.x
N/A
Source:
NVD
CVSS 2.x
1.9 LOW
AV:L/AC:M/Au:N/C:P/I:N/A:N
RedHat/V2
1.9 LOW
AV:L/AC:M/Au:N/C:P/I:N/A:N
RedHat/V3
Ubuntu

The security audit functionality in Red Hat JBoss Enterprise Application Platform (EAP) 6.x before 6.2.1 logs request parameters in plaintext, which might allow local users to obtain passwords by reading the log files.

Affected Software

Name Vendor Start Version End Version
Jboss_enterprise_application_platform Redhat 6.0.0 6.0.0
Jboss_enterprise_application_platform Redhat 6.0.1 6.0.1
Jboss_enterprise_application_platform Redhat 6.1.0 6.1.0
Jboss_enterprise_application_platform Redhat 6.2.0 6.2.0
Red Hat JBoss BPMS 6.0 RedHat eap *
Red Hat JBoss BRMS 6.0 RedHat eap *
Red Hat JBoss Data Grid 6.3 RedHat eap *
Red Hat JBoss Data Virtualization 6.0 RedHat eap *
Red Hat JBoss Enterprise Application Platform 6.2 RedHat *
Red Hat JBoss Enterprise Application Platform 6.2 for RHEL 5 RedHat jboss-as-web-0:7.3.1-4.Final_redhat_4.1.ep6.el5 *
Red Hat JBoss Enterprise Application Platform 6.2 for RHEL 6 RedHat jboss-as-web-0:7.3.1-4.Final_redhat_4.1.ep6.el6 *
Red Hat JBoss Fuse Service Works 6.0 RedHat eap *
Red Hat JBoss Operations Network 3.2 RedHat *
Red Hat JBoss Portal 6.2 RedHat eap *

References