CVE-2014-0058
published 2014-02-26CVE-2014-0058: The security audit functionality in Red Hat JBoss Enterprise Application Platform (EAP) 6.x before 6.2.1 logs request parameters in plaintext, which might…
PriorityP45low1.9CVSS 2.0
AVLACMAuNCPINAN
EPSS
0.35%
26.9th percentile
The security audit functionality in Red Hat JBoss Enterprise Application Platform (EAP) 6.x before 6.2.1 logs request parameters in plaintext, which might allow local users to obtain passwords by reading the log files.
Affected
4 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| redhat | jboss_enterprise_application_platform | — | — |
| redhat | jboss_enterprise_application_platform | — | — |
| redhat | jboss_enterprise_application_platform | — | — |
| redhat | jboss_enterprise_application_platform | — | — |
CVSS provenance
nvdv2.01.9LOWAV:L/AC:M/Au:N/C:P/I:N/A:N
vendor_redhat1.9LOW
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-42c9-mw7r-66f3: The security audit functionality in Red Hat JBoss Enterprise Application Platform (EAP) 6
ghsa_unreviewed·2022-05-17
CVE-2014-0058 [LOW] GHSA-42c9-mw7r-66f3: The security audit functionality in Red Hat JBoss Enterprise Application Platform (EAP) 6
The security audit functionality in Red Hat JBoss Enterprise Application Platform (EAP) 6.x before 6.2.1 logs request parameters in plaintext, which might allow local users to obtain passwords by reading the log files.
Red Hat
EAP6: Plain text password logging during security audit
vendor_redhat·2014-02-24·CVSS 1.9
CVE-2014-0058 [LOW] EAP6: Plain text password logging during security audit
EAP6: Plain text password logging during security audit
The security audit functionality in Red Hat JBoss Enterprise Application Platform (EAP) 6.x before 6.2.1 logs request parameters in plaintext, which might allow local users to obtain passwords by reading the log files.
It was found that the security audit functionality logged request parameters in plain text. This may have caused passwords to be included in the audit log files when using BASIC or FORM-based authentication. A local attacker with access to audit log files could possibly use this flaw to obtain application or server authentication credentials.
Package: audit (Red Hat JBoss Enterprise Application Platform 5) - Not affected
Package: eap (Red Hat JBoss Operations Network 3) - Affected
No detection rules found.
No public exploits indexed.
http://rhn.redhat.com/errata/RHSA-2014-0204.htmlhttp://rhn.redhat.com/errata/RHSA-2014-0205.htmlhttp://rhn.redhat.com/errata/RHSA-2015-0034.htmlhttp://www.securityfocus.com/bid/65762http://rhn.redhat.com/errata/RHSA-2014-0204.htmlhttp://rhn.redhat.com/errata/RHSA-2014-0205.htmlhttp://rhn.redhat.com/errata/RHSA-2015-0034.htmlhttp://www.securityfocus.com/bid/65762
2014-02-26
Published