Vulnerability Name: | CVE-2014-0058 (CCN-91575) | ||||||||
Assigned: | 2013-12-03 | ||||||||
Published: | 2014-02-24 | ||||||||
Updated: | 2017-01-07 | ||||||||
Summary: | The security audit functionality in Red Hat JBoss Enterprise Application Platform (EAP) 6.x before 6.2.1 logs request parameters in plaintext, which might allow local users to obtain passwords by reading the log files. | ||||||||
CVSS v3 Severity: | 4.0 Medium (CCN CVSS v3.1 Vector: CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N)
| ||||||||
CVSS v2 Severity: | 1.9 Low (CVSS v2 Vector: AV:L/AC:M/Au:N/C:P/I:N/A:N) 1.4 Low (Temporal CVSS v2 Vector: AV:L/AC:M/Au:N/C:P/I:N/A:N/E:U/RL:OF/RC:C)
1.6 Low (CCN Temporal CVSS v2 Vector: AV:L/AC:L/Au:N/C:P/I:N/A:N/E:U/RL:OF/RC:C)
| ||||||||
Vulnerability Type: | CWE-310 | ||||||||
Vulnerability Consequences: | Obtain Information | ||||||||
References: | Source: MITRE Type: CNA CVE-2014-0058 Source: REDHAT Type: Vendor Advisory RHSA-2014:0204 Source: REDHAT Type: Vendor Advisory RHSA-2014:0205 Source: CCN Type: RHSA-2015-0034 Moderate: Red Hat JBoss Data Virtualization 6.0.0 security update Source: REDHAT Type: Vendor Advisory RHSA-2015:0034 Source: BID Type: UNKNOWN 65762 Source: CCN Type: BID-65762 JBoss Enterprise Application Platform Plain Text Password Local Information Disclosure Vulnerability Source: CCN Type: Red Hat Bugzilla Bug 1063641 CVE-2014-0058 Red Hat JBoss EAP6: Plain text password logging during security audit Source: XF Type: UNKNOWN redhat-eap-cve20140058-info-disc(91575) | ||||||||
Vulnerable Configuration: | Configuration 1: Configuration CCN 1: Denotes that component is vulnerable | ||||||||
BACK |