CVE-2014-0059
published 2014-11-17CVE-2014-0059: JBoss SX and PicketBox, as used in Red Hat JBoss Enterprise Application Platform (EAP) before 6.2.3, use world-readable permissions on audit.log, which allows…
PriorityP44low2.1CVSS 2.0
AVLACLAuNCPINAN
EPSS
0.35%
26.9th percentile
JBoss SX and PicketBox, as used in Red Hat JBoss Enterprise Application Platform (EAP) before 6.2.3, use world-readable permissions on audit.log, which allows local users to obtain sensitive information by reading this file.
Affected
1 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| redhat | jboss_enterprise_application_platform | <= 6.2.2 | — |
CVSS provenance
nvdv2.02.1LOWAV:L/AC:L/Au:N/C:P/I:N/A:N
vendor_redhat2.1LOW
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-h9mr-9rp7-76qj: JBoss SX and PicketBox, as used in Red Hat JBoss Enterprise Application Platform (EAP) before 6
ghsa_unreviewed·2022-05-17
CVE-2014-0059 [LOW] CWE-200 GHSA-h9mr-9rp7-76qj: JBoss SX and PicketBox, as used in Red Hat JBoss Enterprise Application Platform (EAP) before 6
JBoss SX and PicketBox, as used in Red Hat JBoss Enterprise Application Platform (EAP) before 6.2.3, use world-readable permissions on audit.log, which allows local users to obtain sensitive information by reading this file.
Red Hat
JBossSX/PicketBox: World readable audit.log file
vendor_redhat·2014-05-27·CVSS 2.1
CVE-2014-0059 [LOW] CWE-532 JBossSX/PicketBox: World readable audit.log file
JBossSX/PicketBox: World readable audit.log file
JBoss SX and PicketBox, as used in Red Hat JBoss Enterprise Application Platform (EAP) before 6.2.3, use world-readable permissions on audit.log, which allows local users to obtain sensitive information by reading this file.
It was found that the security auditing functionality provided by PicketBox and JBossSX, both security frameworks for Java applications, used a world-readable audit.log file to record sensitive information. A local user could possibly use this flaw to gain access to the sensitive information in the audit.log file.
Package: eap (Red Hat JBoss Data Virtualization 6) - Affected
Package: eap (Red Hat JBoss Fuse Service Works 6) - Affected
No detection rules found.
No public exploits indexed.
http://rhn.redhat.com/errata/RHSA-2014-0563.htmlhttp://rhn.redhat.com/errata/RHSA-2014-0564.htmlhttp://rhn.redhat.com/errata/RHSA-2014-0565.htmlhttp://rhn.redhat.com/errata/RHSA-2015-0675.htmlhttp://rhn.redhat.com/errata/RHSA-2015-0850.htmlhttp://rhn.redhat.com/errata/RHSA-2015-0851.htmlhttp://rhn.redhat.com/errata/RHSA-2014-0563.htmlhttp://rhn.redhat.com/errata/RHSA-2014-0564.htmlhttp://rhn.redhat.com/errata/RHSA-2014-0565.htmlhttp://rhn.redhat.com/errata/RHSA-2015-0675.htmlhttp://rhn.redhat.com/errata/RHSA-2015-0850.htmlhttp://rhn.redhat.com/errata/RHSA-2015-0851.html
2014-11-17
Published