CVE-2019-14885Log File Information Exposure in Redhat Jboss Enterprise Application Platform

Severity
4.3MEDIUMNVD
EPSS
0.3%
top 44.62%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedJan 23
Latest updateMay 24

Description

A flaw was found in the JBoss EAP Vault system in all versions before 7.2.6.GA. Confidential information of the system property's security attribute value is revealed in the JBoss EAP log file when executing a JBoss CLI 'reload' command. This flaw can lead to the exposure of confidential information.

CVSS vector

CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:NExploitability: 2.8 | Impact: 1.4

Affected Packages3 packages

CVEListV5red_hat/jboss_eapAll versions before 7.2.6.GA

🔴Vulnerability Details

2
GHSA
GHSA-cxpp-v3rm-fq33: A flaw was found in the JBoss EAP Vault system in all versions before 72022-05-24
CVEList
CVE-2019-14885: A flaw was found in the JBoss EAP Vault system in all versions before 72020-01-23

📋Vendor Advisories

1
Red Hat
EAP: Vault system property security attribute value is revealed on CLI 'reload' command2020-01-20

💬Community

1
Bugzilla
CVE-2019-14885 JBoss EAP: Vault system property security attribute value is revealed on CLI 'reload' command2019-11-11
CVE-2019-14885 — Log File Information Exposure | cvebase