Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2013-1921

Опубликовано: 04 сент. 2013
Источник: redhat
CVSS2: 1.7
EPSS Низкий

Описание

PicketBox, as used in Red Hat JBoss Enterprise Application Platform before 6.1.1, allows local users to obtain the admin encryption key by reading the Vault data file.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat JBoss Data Grid 6picketboxAffected
Red Hat JBoss Portal 6picketboxAffected
Red Hat JBoss Data Grid 6.2FixedRHSA-2014:002915.01.2014
Red Hat JBoss Enterprise Application Platform 6.1FixedRHSA-2013:120904.09.2013
Red Hat JBoss Enterprise Application Platform 6 for RHEL 5apache-commons-beanutilsFixedRHSA-2013:120704.09.2013
Red Hat JBoss Enterprise Application Platform 6 for RHEL 5apache-commons-daemon-jsvc-eap6FixedRHSA-2013:120704.09.2013
Red Hat JBoss Enterprise Application Platform 6 for RHEL 5apache-cxfFixedRHSA-2013:120704.09.2013
Red Hat JBoss Enterprise Application Platform 6 for RHEL 5apache-cxf-xjc-utilsFixedRHSA-2013:120704.09.2013
Red Hat JBoss Enterprise Application Platform 6 for RHEL 5hibernate4FixedRHSA-2013:120704.09.2013
Red Hat JBoss Enterprise Application Platform 6 for RHEL 5hornetqFixedRHSA-2013:120704.09.2013

Показывать по

Дополнительная информация

Статус:

Low
https://bugzilla.redhat.com/show_bug.cgi?id=948106PicketBox: Insecure storage of masked passwords

EPSS

Процентиль: 15%
0.00239
Низкий

1.7 Low

CVSS2

Связанные уязвимости

nvd
почти 13 лет назад

PicketBox, as used in Red Hat JBoss Enterprise Application Platform before 6.1.1, allows local users to obtain the admin encryption key by reading the Vault data file.

github
около 4 лет назад

PicketBox, as used in Red Hat JBoss Enterprise Application Platform before 6.1.1, allows local users to obtain the admin encryption key by reading the Vault data file.

EPSS

Процентиль: 15%
0.00239
Низкий

1.7 Low

CVSS2