The GUI installer in JBoss Enterprise Application Platform (EAP) and Enterprise Web Platform (EWP) 5.2.0 and possibly 5.1.2 uses world-readable permissions for the auto-install XML file, which allows local users to obtain the administrator password and the sucker password by reading this file.
The product exposes sensitive information to an actor that is not explicitly authorized to have access to that information.
Link | Tags |
---|---|
http://rhn.redhat.com/errata/RHSA-2013-0206.html | vendor advisory |
http://www.osvdb.org/89698 | vdb entry |
http://secunia.com/advisories/52041 | third party advisory vendor advisory |
http://rhn.redhat.com/errata/RHSA-2013-0833.html | vendor advisory |
http://rhn.redhat.com/errata/RHSA-2013-0207.html | vendor advisory |
https://bugzilla.redhat.com/show_bug.cgi?id=903073 | |
https://exchange.xforce.ibmcloud.com/vulnerabilities/81725 | vdb entry |
http://www.securityfocus.com/bid/57652 | vdb entry |