EC2 Amazon Machine Image (AMI) in JBoss Enterprise Application Platform (EAP) 5.1.2 uses 755 permissions for /var/cache/jboss-ec2-eap/, which allows local users to read sensitive information such as Amazon Web Services (AWS) credentials by reading files in the directory.
Weaknesses in this category are related to the management of permissions, privileges, and other security features that are used to perform access control.
Link | Tags |
---|---|
http://rhn.redhat.com/errata/RHSA-2012-1376.html | vendor advisory |
http://www.securityfocus.com/bid/55945 | vdb entry |
http://secunia.com/advisories/51016 | third party advisory vendor advisory |
https://exchange.xforce.ibmcloud.com/vulnerabilities/79398 | vdb entry |
http://www.osvdb.org/86409 | vdb entry |