2.1
CVSSv2

CVE-2014-0059

Published: 17/11/2014 Updated: 01/10/2016
CVSS v2 Base Score: 2.1 | Impact Score: 2.9 | Exploitability Score: 3.9
VMScore: 187
Vector: AV:L/AC:L/Au:N/C:P/I:N/A:N

Vulnerability Summary

JBoss SX and PicketBox, as used in Red Hat JBoss Enterprise Application Platform (EAP) prior to 6.2.3, use world-readable permissions on audit.log, which allows local users to obtain sensitive information by reading this file.

Vulnerable Product Search on Vulmon Subscribe to Product

redhat jboss enterprise application platform

Vendor Advisories

It was found that the security auditing functionality provided by PicketBox and JBossSX, both security frameworks for Java applications, used a world-readable auditlog file to record sensitive information A local user could possibly use this flaw to gain access to the sensitive information in the auditlog file ...