2.1
CVSSv2

CVE-2013-0218

Published: 05/02/2013 Updated: 29/08/2017
CVSS v2 Base Score: 2.1 | Impact Score: 2.9 | Exploitability Score: 3.9
VMScore: 187
Vector: AV:L/AC:L/Au:N/C:P/I:N/A:N

Vulnerability Summary

The GUI installer in JBoss Enterprise Application Platform (EAP) and Enterprise Web Platform (EWP) 5.2.0 and possibly 5.1.2 uses world-readable permissions for the auto-install XML file, which allows local users to obtain the administrator password and the sucker password by reading this file.

Vulnerable Product Search on Vulmon Subscribe to Product

redhat jboss enterprise application platform 5.2.0

redhat jboss enterprise application platform 5.1.2

redhat jboss enterprise web platform 5.1.2

redhat jboss enterprise web platform 5.2.0

Vendor Advisories

Synopsis Low: JBoss Enterprise Application Platform 520 security update Type/Severity Security Advisory: Low Topic An update for JBoss Enterprise Application Platform 520 which fixes onesecurity issue is now available from the Red Hat Customer PortalThe Red Hat Security Response Team has rated this upd ...
Synopsis Low: JBoss Enterprise Web Platform 520 security update Type/Severity Security Advisory: Low Topic An update for JBoss Enterprise Web Platform 520 which fixes one securityissue is now available from the Red Hat Customer PortalThe Red Hat Security Response Team has rated this update as having lo ...