CVE-2013-1921Redhat Jboss Enterprise Application Platform vulnerability

CWE-3105 documents5 sources
Severity
1.9LOWNVD
EPSS
0.1%
top 78.05%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedSep 28
Latest updateMay 17

Description

PicketBox, as used in Red Hat JBoss Enterprise Application Platform before 6.1.1, allows local users to obtain the admin encryption key by reading the Vault data file.

CVSS vector

AV:L/AC:M/C:P/I:N/A:NExploitability: 3.4 | Impact: 2.9

Affected Packages1 packages

🔴Vulnerability Details

2
GHSA
GHSA-p398-vx5x-3pgp: PicketBox, as used in Red Hat JBoss Enterprise Application Platform before 62022-05-17
CVEList
CVE-2013-1921: PicketBox, as used in Red Hat JBoss Enterprise Application Platform before 62013-09-28

📋Vendor Advisories

1
Red Hat
PicketBox: Insecure storage of masked passwords2013-09-04

💬Community

1
Bugzilla
CVE-2013-1921 JBoss PicketBox: Insecure storage of masked passwords2013-04-04
CVE-2013-1921 — Redhat vulnerability | cvebase