The default configuration for the Command Line Interface in Red Hat Enterprise Application Platform before 6.4.0 and WildFly (formerly JBoss Application Server) uses weak permissions for .jboss-cli-history, which allows local users to obtain sensitive information via unspecified vectors.
References
Configurations
Information
Published : 2015-04-21 10:59
Updated : 2015-10-13 09:51
NVD link : CVE-2014-3586
Mitre link : CVE-2014-3586
JSON object : View
CWE
CWE-264
Permissions, Privileges, and Access Controls
Products Affected
redhat
- jboss_enterprise_application_platform