CVE-2014-3586
published 2015-04-21CVE-2014-3586: The default configuration for the Command Line Interface in Red Hat Enterprise Application Platform before 6.4.0 and WildFly (formerly JBoss Application…
PriorityP46low2.1CVSS 2.0
AVLACLAuNCPINAN
EPSS
0.37%
29.5th percentile
The default configuration for the Command Line Interface in Red Hat Enterprise Application Platform before 6.4.0 and WildFly (formerly JBoss Application Server) uses weak permissions for .jboss-cli-history, which allows local users to obtain sensitive information via unspecified vectors.
Affected
1 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| redhat | jboss_enterprise_application_platform | <= 6.3.3 | — |
CVSS provenance
nvdv2.02.1LOWAV:L/AC:L/Au:N/C:P/I:N/A:N
vendor_redhat2.1LOW
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-q4g2-rhrf-wvj6: The default configuration for the Command Line Interface in Red Hat Enterprise Application Platform before 6
ghsa_unreviewed·2022-05-17
CVE-2014-3586 [LOW] GHSA-q4g2-rhrf-wvj6: The default configuration for the Command Line Interface in Red Hat Enterprise Application Platform before 6
The default configuration for the Command Line Interface in Red Hat Enterprise Application Platform before 6.4.0 and WildFly (formerly JBoss Application Server) uses weak permissions for .jboss-cli-history, which allows local users to obtain sensitive information via unspecified vectors.
Red Hat
CLI: Insecure default permissions on history file
vendor_redhat·2015-03-10·CVSS 2.1
CVE-2014-3586 [LOW] CWE-732 CLI: Insecure default permissions on history file
CLI: Insecure default permissions on history file
The default configuration for the Command Line Interface in Red Hat Enterprise Application Platform before 6.4.0 and WildFly (formerly JBoss Application Server) uses weak permissions for .jboss-cli-history, which allows local users to obtain sensitive information via unspecified vectors.
It was found that the Command Line Interface, as provided by Red Hat Enterprise Application Platform, created a history file named .jboss-cli-history in the user's home directory with insecure default file permissions. This could allow a malicious local user to gain information otherwise not accessible to them.
Package: jboss-as-cli (Red Hat JBoss Data Grid 6) - Affected
Package: jboss-as-cli (Red Hat JBoss Operations Network 3) - Affected
No detection rules found.
No public exploits indexed.
http://rhn.redhat.com/errata/RHSA-2015-0846.htmlhttp://rhn.redhat.com/errata/RHSA-2015-0847.htmlhttp://rhn.redhat.com/errata/RHSA-2015-0848.htmlhttp://rhn.redhat.com/errata/RHSA-2015-0849.htmlhttp://www.securitytracker.com/id/1032183https://bugzilla.redhat.com/show_bug.cgi?id=1126687http://rhn.redhat.com/errata/RHSA-2015-0846.htmlhttp://rhn.redhat.com/errata/RHSA-2015-0847.htmlhttp://rhn.redhat.com/errata/RHSA-2015-0848.htmlhttp://rhn.redhat.com/errata/RHSA-2015-0849.htmlhttp://www.securitytracker.com/id/1032183https://bugzilla.redhat.com/show_bug.cgi?id=1126687
2015-04-21
Published