CVE-2012-3427
published 2014-02-02CVE-2012-3427: EC2 Amazon Machine Image (AMI) in JBoss Enterprise Application Platform (EAP) 5.1.2 uses 755 permissions for /var/cache/jboss-ec2-eap/, which allows local…
PriorityP46low2.1CVSS 2.0
AVLACLAuNCPINAN
EPSS
0.35%
27.9th percentile
EC2 Amazon Machine Image (AMI) in JBoss Enterprise Application Platform (EAP) 5.1.2 uses 755 permissions for /var/cache/jboss-ec2-eap/, which allows local users to read sensitive information such as Amazon Web Services (AWS) credentials by reading files in the directory.
Affected
1 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| redhat | jboss_enterprise_application_platform | — | — |
CVSS provenance
nvdv2.02.1LOWAV:L/AC:L/Au:N/C:P/I:N/A:N
vendor_redhat2.1LOW
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Red Hat
CVE-2012-3427: EC2 Amazon Machine Image (AMI) in JBoss Enterprise Application Platform (EAP) 5
vendor_redhat·2014-02-02·CVSS 2.1
CVE-2012-3427 [LOW] CWE-276 CVE-2012-3427: EC2 Amazon Machine Image (AMI) in JBoss Enterprise Application Platform (EAP) 5
EC2 Amazon Machine Image (AMI) in JBoss Enterprise Application Platform (EAP) 5.1.2 uses 755 permissions for /var/cache/jboss-ec2-eap/, which allows local users to read sensitive information such as Amazon Web Services (AWS) credentials by reading files in the directory.
A flaw was found in JBoss Enterprise Application Platform (EAP) and EC2 Amazon Machine Image (AMI). Incorrect permissions (755) for the /var/cache/jboss-ec2-eap/ directory allow a local user to read sensitive files. This vulnerability can lead to information disclosure, specifically exposing Amazon Web Services (AWS) credentials.
Mitigation: Mitigation for this issue is either not available or the currently available options do not meet the Red Hat Product Security criteria comprising ease of use and deployment, applicab
GHSA
GHSA-mhvm-wr2g-3xfq: EC2 Amazon Machine Image (AMI) in JBoss Enterprise Application Platform (EAP) 5
ghsa_unreviewed·2022-05-17
CVE-2012-3427 [LOW] GHSA-mhvm-wr2g-3xfq: EC2 Amazon Machine Image (AMI) in JBoss Enterprise Application Platform (EAP) 5
EC2 Amazon Machine Image (AMI) in JBoss Enterprise Application Platform (EAP) 5.1.2 uses 755 permissions for /var/cache/jboss-ec2-eap/, which allows local users to read sensitive information such as Amazon Web Services (AWS) credentials by reading files in the directory.
No detection rules found.
No public exploits indexed.
http://rhn.redhat.com/errata/RHSA-2012-1376.htmlhttp://secunia.com/advisories/51016http://www.osvdb.org/86409http://www.securityfocus.com/bid/55945https://exchange.xforce.ibmcloud.com/vulnerabilities/79398http://rhn.redhat.com/errata/RHSA-2012-1376.htmlhttp://secunia.com/advisories/51016http://www.osvdb.org/86409http://www.securityfocus.com/bid/55945https://exchange.xforce.ibmcloud.com/vulnerabilities/79398
2014-02-02
Published