CVE-2012-0034
published 2013-02-05CVE-2012-0034: The NonManagedConnectionFactory in JBoss Enterprise Application Platform (EAP) 5.1.2 and 5.2.0, Web Platform (EWP) 5.1.2 and 5.2.0, and BRMS Platform before…
PriorityP47low2.1CVSS 2.0
AVLACLAuNCPINAN
EPSS
0.40%
32.3th percentile
The NonManagedConnectionFactory in JBoss Enterprise Application Platform (EAP) 5.1.2 and 5.2.0, Web Platform (EWP) 5.1.2 and 5.2.0, and BRMS Platform before 5.3.1 logs the username and password in cleartext when an exception is thrown, which allows local users to obtain sensitive information by reading the log file.
Affected
5 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| redhat | jboss_enterprise_application_platform | — | — |
| redhat | jboss_enterprise_application_platform | — | — |
| redhat | jboss_enterprise_brms_platform | <= 5.3.0 | — |
| redhat | jboss_enterprise_web_platform | — | — |
| redhat | jboss_enterprise_web_platform | — | — |
CVSS provenance
nvdv2.02.1LOWAV:L/AC:L/Au:N/C:P/I:N/A:N
vendor_redhat2.1LOW
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-hcgg-293c-27px: The NonManagedConnectionFactory in JBoss Enterprise Application Platform (EAP) 5
ghsa_unreviewed·2022-05-04
CVE-2012-0034 [LOW] GHSA-hcgg-293c-27px: The NonManagedConnectionFactory in JBoss Enterprise Application Platform (EAP) 5
The NonManagedConnectionFactory in JBoss Enterprise Application Platform (EAP) 5.1.2 and 5.2.0, Web Platform (EWP) 5.1.2 and 5.2.0, and BRMS Platform before 5.3.1 logs the username and password in cleartext when an exception is thrown, which allows local users to obtain sensitive information by reading the log file.
Red Hat
Cache: NonManagedConnectionFactory will log password in clear text when an exception occurs
vendor_redhat·2011-12-30·CVSS 2.1
CVE-2012-0034 [LOW] Cache: NonManagedConnectionFactory will log password in clear text when an exception occurs
Cache: NonManagedConnectionFactory will log password in clear text when an exception occurs
The NonManagedConnectionFactory in JBoss Enterprise Application Platform (EAP) 5.1.2 and 5.2.0, Web Platform (EWP) 5.1.2 and 5.2.0, and BRMS Platform before 5.3.1 logs the username and password in cleartext when an exception is thrown, which allows local users to obtain sensitive information by reading the log file.
Package: jbosscache (Red Hat JBoss BRMS 5) - Affected
Package: jbosscache (Red Hat JBoss Portal 5) - Will not fix
Package: jbosscache (Red Hat JBoss SOA Platform 5) - Affected
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2012-0034 JBoss Cache: NonManagedConnectionFactory will log password in clear text when an exception occurs
bugzilla·2012-01-10·CVSS 2.1
CVE-2012-0034 [LOW] CVE-2012-0034 JBoss Cache: NonManagedConnectionFactory will log password in clear text when an exception occurs
CVE-2012-0034 JBoss Cache: NonManagedConnectionFactory will log password in clear text when an exception occurs
It was found that the NonManagedConnectionFactory would log the username and password in cleartext when an exception was thrown. A local attacker could exploit this flaw by reading the password from the log file, if they had appropriate permissions to read the log file.
Discussion:
This issue has been addressed in following products:
JBoss Enterprise Application Platform 5.1.2
Via RHSA-2012:0108 https://rhn.redhat.com/errata/RHSA-2012-0108.html
---
This issue has been addressed in following products:
JBoss Enterprise Web Platform 5.1.2
Via RHSA-2012:1072 https://rhn.redhat.com/errata/RHSA-2012-1072.html
---
This issue has been addressed in following products:
JBEAP 5
Bugzilla
CVE-2011-3550 Oracle/IBM JDK: unspecified vulnerability fixed in 6u29 (AWT)
bugzilla·2011-10-19·CVSS 7.6
CVE-2011-3550 [HIGH] CVE-2011-3550 Oracle/IBM JDK: unspecified vulnerability fixed in 6u29 (AWT)
CVE-2011-3550 Oracle/IBM JDK: unspecified vulnerability fixed in 6u29 (AWT)
Update 29 of Oracle/Sun Java fixes an unspecified vulnerability in the AWT component (CVE-2011-3550). Upstream has CVSSv2 scored this issue as: 5.1/AV:N/AC:H/Au:N/C:P/I:P/A:P
Discussion:
External References:
http://www.oracle.com/technetwork/topics/security/javacpuoct2011-443431.html
---
This issue has been addressed in following products:
Supplementary for Red Hat Enterprise Linux 6
Supplementary for Red Hat Enterprise Linux 5
Extras for RHEL 4
Via RHSA-2011:1384 https://rhn.redhat.com/errata/RHSA-2011-1384.html
---
This issue has been addressed in following products:
Supplementary for Red Hat Enterprise Linux 5
Extras for RHEL 4
Supplementary for Red Hat Enterprise Linux 6
Via RHSA-2012:0034 https://r
http://rhn.redhat.com/errata/RHSA-2012-0108.htmlhttp://rhn.redhat.com/errata/RHSA-2012-1072.htmlhttp://rhn.redhat.com/errata/RHSA-2013-0191.htmlhttp://rhn.redhat.com/errata/RHSA-2013-0192.htmlhttp://rhn.redhat.com/errata/RHSA-2013-0193.htmlhttp://rhn.redhat.com/errata/RHSA-2013-0195.htmlhttp://rhn.redhat.com/errata/RHSA-2013-0196.htmlhttp://rhn.redhat.com/errata/RHSA-2013-0197.htmlhttp://rhn.redhat.com/errata/RHSA-2013-0221.htmlhttp://rhn.redhat.com/errata/RHSA-2013-0533.htmlhttp://secunia.com/advisories/51984http://secunia.com/advisories/52054http://www.osvdb.org/78259http://www.securityfocus.com/bid/51392https://bugzilla.redhat.com/show_bug.cgi?id=772835https://issues.jboss.org/browse/JBCACHE-1612http://rhn.redhat.com/errata/RHSA-2012-0108.htmlhttp://rhn.redhat.com/errata/RHSA-2012-1072.htmlhttp://rhn.redhat.com/errata/RHSA-2013-0191.htmlhttp://rhn.redhat.com/errata/RHSA-2013-0192.htmlhttp://rhn.redhat.com/errata/RHSA-2013-0193.htmlhttp://rhn.redhat.com/errata/RHSA-2013-0195.htmlhttp://rhn.redhat.com/errata/RHSA-2013-0196.htmlhttp://rhn.redhat.com/errata/RHSA-2013-0197.htmlhttp://rhn.redhat.com/errata/RHSA-2013-0221.htmlhttp://rhn.redhat.com/errata/RHSA-2013-0533.htmlhttp://secunia.com/advisories/51984http://secunia.com/advisories/52054http://www.osvdb.org/78259http://www.securityfocus.com/bid/51392https://bugzilla.redhat.com/show_bug.cgi?id=772835https://issues.jboss.org/browse/JBCACHE-1612
2013-02-05
Published