Vulnerability Name:

CVE-2013-0218 (CCN-81725)

Assigned:2012-12-06
Published:2013-01-30
Updated:2017-08-29
Summary:The GUI installer in JBoss Enterprise Application Platform (EAP) and Enterprise Web Platform (EWP) 5.2.0 and possibly 5.1.2 uses world-readable permissions for the auto-install XML file, which allows local users to obtain the administrator password and the sucker password by reading this file.
Per http://rhn.redhat.com/errata/RHSA-2013-0206.html
"An update for JBoss Enterprise Application Platform 5.2.0 which fixes one
security issue is now available from the Red Hat Customer Portal."

Per http://rhn.redhat.com/errata/RHSA-2013-0207.html
"An update for JBoss Enterprise Web Platform 5.2.0 which fixes one security
issue is now available from the Red Hat Customer Portal."
CVSS v3 Severity:4.0 Medium (CCN CVSS v3.1 Vector: CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N)
Exploitability Metrics:Attack Vector (AV): Local
Attack Complexity (AC): Low
Privileges Required (PR): None
User Interaction (UI): None
Scope:Scope (S): Unchanged
Impact Metrics:Confidentiality (C): Low
Integrity (I): None
Availibility (A): None
CVSS v2 Severity:2.1 Low (CVSS v2 Vector: AV:L/AC:L/Au:N/C:P/I:N/A:N)
1.6 Low (Temporal CVSS v2 Vector: AV:L/AC:L/Au:N/C:P/I:N/A:N/E:U/RL:OF/RC:C)
Exploitability Metrics:Access Vector (AV): Local
Access Complexity (AC): Low
Authentication (Au): None
Impact Metrics:Confidentiality (C): Partial
Integrity (I): None
Availibility (A): None
2.1 Low (CCN CVSS v2 Vector: AV:L/AC:L/Au:N/C:P/I:N/A:N)
1.6 Low (CCN Temporal CVSS v2 Vector: AV:L/AC:L/Au:N/C:P/I:N/A:N/E:U/RL:OF/RC:C)
Exploitability Metrics:Access Vector (AV): Local
Access Complexity (AC): Low
Athentication (Au): None
Impact Metrics:Confidentiality (C): Partial
Integrity (I): None
Availibility (A): None
Vulnerability Type:CWE-200
Vulnerability Consequences:Obtain Information
References:Source: MITRE
Type: CNA
CVE-2013-0218

Source: REDHAT
Type: Vendor Advisory
RHSA-2013:0206

Source: REDHAT
Type: Vendor Advisory
RHSA-2013:0207

Source: REDHAT
Type: UNKNOWN
RHSA-2013:0833

Source: CCN
Type: SA52041
Red Hat update for JBoss Enterprise Application Platform and JBoss Enterprise Web Platform

Source: SECUNIA
Type: Vendor Advisory
52041

Source: OSVDB
Type: UNKNOWN
89698

Source: BID
Type: UNKNOWN
57652

Source: CCN
Type: BID-57652
RedHat Multiple JBoss Enterprise Products CVE-2013-0218 Local Information Disclosure Vulnerability

Source: MISC
Type: UNKNOWN
https://bugzilla.redhat.com/show_bug.cgi?id=903073

Source: XF
Type: UNKNOWN
jboss-eap-info-disc(81725)

Source: XF
Type: UNKNOWN
jboss-eap-info-disc(81725)

Source: CCN
Type: RHSA-2013:0206-1
Low: JBoss Enterprise Application Platform 5.2.0 security update

Source: CCN
Type: RHSA-2013:0207-1
Low: JBoss Enterprise Web Platform 5.2.0 security update

Vulnerable Configuration:Configuration 1:
  • cpe:/a:redhat:jboss_enterprise_application_platform:5.1.2:*:*:*:*:*:*:*
  • OR cpe:/a:redhat:jboss_enterprise_application_platform:5.2.0:*:*:*:*:*:*:*

  • Configuration 2:
  • cpe:/a:redhat:jboss_enterprise_web_platform:5.1.2:*:*:*:*:*:*:*
  • OR cpe:/a:redhat:jboss_enterprise_web_platform:5.2.0:*:*:*:*:*:*:*

  • Configuration CCN 1:
  • cpe:/a:redhat:jboss_enterprise_web_platform:5.1.2:*:*:*:*:*:*:*
  • OR cpe:/a:redhat:jboss_enterprise_application_platform:5.1.2:*:*:*:*:*:*:*

  • * Denotes that component is vulnerable
    Oval Definitions
    Definition IDClassTitleLast Modified
    oval:com.ubuntu.precise:def:20130218000
    V
    CVE-2013-0218 on Ubuntu 12.04 LTS (precise) - medium.
    2013-02-05
    BACK
    redhat jboss enterprise application platform 5.1.2
    redhat jboss enterprise application platform 5.2.0
    redhat jboss enterprise web platform 5.1.2
    redhat jboss enterprise web platform 5.2.0
    redhat jboss enterprise web platform 5.1.2
    redhat jboss enterprise application platform 5.1.2