Jboss EAP Exposure of Sensitive Information to an Unauthorized Actor Vulnerability - CVE-2014-0059 - Vulnerability Database

Jboss EAP Exposure of Sensitive Information to an Unauthorized Actor Vulnerability - CVE-2014-0059

Low
Reference: CVE-2014-0059
Title: Jboss EAP Exposure of Sensitive Information to an Unauthorized Actor Vulnerability
Overview:

JBoss SX and PicketBox as used in Red Hat JBoss Enterprise Application Platform (EAP) before 6.2.3 use world-readable permissions on audit.log which allows local users to obtain sensitive information by reading this file.