2.1
CVSSv2

CVE-2014-3586

Published: 21/04/2015 Updated: 13/10/2015
CVSS v2 Base Score: 2.1 | Impact Score: 2.9 | Exploitability Score: 3.9
VMScore: 187
Vector: AV:L/AC:L/Au:N/C:P/I:N/A:N

Vulnerability Summary

The default configuration for the Command Line Interface in Red Hat Enterprise Application Platform prior to 6.4.0 and WildFly (formerly JBoss Application Server) uses weak permissions for .jboss-cli-history, which allows local users to obtain sensitive information via unspecified vectors.

Vulnerable Product Search on Vulmon Subscribe to Product

redhat jboss enterprise application platform

Vendor Advisories

It was found that the Command Line Interface, as provided by Red Hat Enterprise Application Platform, created a history file named jboss-cli-history in the user's home directory with insecure default file permissions This could allow a malicious local user to gain information otherwise not accessible to them ...