Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2012-0034

Опубликовано: 30 дек. 2011
Источник: redhat
CVSS2: 1
EPSS Низкий

Описание

The NonManagedConnectionFactory in JBoss Enterprise Application Platform (EAP) 5.1.2 and 5.2.0, Web Platform (EWP) 5.1.2 and 5.2.0, and BRMS Platform before 5.3.1 logs the username and password in cleartext when an exception is thrown, which allows local users to obtain sensitive information by reading the log file.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat JBoss BRMS 5jbosscacheAffected
Red Hat JBoss Portal 5jbosscacheWill not fix
Red Hat JBoss SOA Platform 5jbosscacheAffected
JBEWP 5 for RHEL 5aopallianceFixedRHSA-2013:019624.01.2013
JBEWP 5 for RHEL 5apache-cxfFixedRHSA-2013:019624.01.2013
JBEWP 5 for RHEL 5bsh2FixedRHSA-2013:019624.01.2013
JBEWP 5 for RHEL 5glassfish-jaxbFixedRHSA-2013:019624.01.2013
JBEWP 5 for RHEL 5google-guiceFixedRHSA-2013:019624.01.2013
JBEWP 5 for RHEL 5hibernate3FixedRHSA-2013:019624.01.2013
JBEWP 5 for RHEL 5hibernate3-annotationsFixedRHSA-2013:019624.01.2013

Показывать по

Дополнительная информация

Статус:

Low
https://bugzilla.redhat.com/show_bug.cgi?id=772835Cache: NonManagedConnectionFactory will log password in clear text when an exception occurs

EPSS

Процентиль: 22%
0.00071
Низкий

1 Low

CVSS2

Связанные уязвимости

ubuntu
около 13 лет назад

The NonManagedConnectionFactory in JBoss Enterprise Application Platform (EAP) 5.1.2 and 5.2.0, Web Platform (EWP) 5.1.2 and 5.2.0, and BRMS Platform before 5.3.1 logs the username and password in cleartext when an exception is thrown, which allows local users to obtain sensitive information by reading the log file.

nvd
около 13 лет назад

The NonManagedConnectionFactory in JBoss Enterprise Application Platform (EAP) 5.1.2 and 5.2.0, Web Platform (EWP) 5.1.2 and 5.2.0, and BRMS Platform before 5.3.1 logs the username and password in cleartext when an exception is thrown, which allows local users to obtain sensitive information by reading the log file.

github
почти 4 года назад

The NonManagedConnectionFactory in JBoss Enterprise Application Platform (EAP) 5.1.2 and 5.2.0, Web Platform (EWP) 5.1.2 and 5.2.0, and BRMS Platform before 5.3.1 logs the username and password in cleartext when an exception is thrown, which allows local users to obtain sensitive information by reading the log file.

EPSS

Процентиль: 22%
0.00071
Низкий

1 Low

CVSS2

Уязвимость CVE-2012-0034