CVE-2014-0059Sensitive Information Exposure in Redhat Jboss Enterprise Application Platform

Severity
2.1LOWNVD
EPSS
0.1%
top 83.48%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedNov 17
Latest updateMay 17

Description

JBoss SX and PicketBox, as used in Red Hat JBoss Enterprise Application Platform (EAP) before 6.2.3, use world-readable permissions on audit.log, which allows local users to obtain sensitive information by reading this file.

CVSS vector

AV:L/AC:L/C:P/I:N/A:NExploitability: 3.9 | Impact: 2.9

Affected Packages1 packages

🔴Vulnerability Details

2
GHSA
GHSA-h9mr-9rp7-76qj: JBoss SX and PicketBox, as used in Red Hat JBoss Enterprise Application Platform (EAP) before 62022-05-17
CVEList
CVE-2014-0059: JBoss SX and PicketBox, as used in Red Hat JBoss Enterprise Application Platform (EAP) before 62014-11-17

📋Vendor Advisories

1
Red Hat
JBossSX/PicketBox: World readable audit.log file2014-05-27

💬Community

1
Bugzilla
CVE-2014-0059 JBossSX/PicketBox: World readable audit.log file2014-02-11
CVE-2014-0059 — Sensitive Information Exposure | cvebase