Описание
Thermostat before 2.0.0 uses world-readable permissions for the web.xml configuration file, which allows local users to obtain user credentials by reading the file.
It was discovered that the Thermostat web application stored database authentication credentials in a world-readable configuration file. A local user on a system running the Thermostat web application could use this flaw to access and modify monitored JVM data, or perform actions on connected JVMs.
Затронутые пакеты
| Платформа | Пакет | Состояние | Рекомендация | Релиз |
|---|---|---|---|---|
| Red Hat Software Collections | thermostat1-thermostat | Affected | ||
| Red Hat Software Collections for Red Hat Enterprise Linux 6 | thermostat1 | Fixed | RHSA-2015:1052 | 04.06.2015 |
| Red Hat Software Collections for Red Hat Enterprise Linux 6 | thermostat1-apache-commons-fileupload | Fixed | RHSA-2015:1052 | 04.06.2015 |
| Red Hat Software Collections for Red Hat Enterprise Linux 6 | thermostat1-jcommon | Fixed | RHSA-2015:1052 | 04.06.2015 |
| Red Hat Software Collections for Red Hat Enterprise Linux 6 | thermostat1-jfreechart | Fixed | RHSA-2015:1052 | 04.06.2015 |
| Red Hat Software Collections for Red Hat Enterprise Linux 6 | thermostat1-jline2 | Fixed | RHSA-2015:1052 | 04.06.2015 |
| Red Hat Software Collections for Red Hat Enterprise Linux 6 | thermostat1-netty | Fixed | RHSA-2015:1052 | 04.06.2015 |
| Red Hat Software Collections for Red Hat Enterprise Linux 6 | thermostat1-thermostat | Fixed | RHSA-2015:1052 | 04.06.2015 |
| Red Hat Software Collections for Red Hat Enterprise Linux 6.5 EUS | thermostat1 | Fixed | RHSA-2015:1052 | 04.06.2015 |
| Red Hat Software Collections for Red Hat Enterprise Linux 6.5 EUS | thermostat1-apache-commons-fileupload | Fixed | RHSA-2015:1052 | 04.06.2015 |
Показывать по
Дополнительная информация
Статус:
EPSS
2.1 Low
CVSS2
Связанные уязвимости
Thermostat before 2.0.0 uses world-readable permissions for the web.xml configuration file, which allows local users to obtain user credentials by reading the file.
Thermostat before 2.0.0 uses world-readable permissions for the web.xml configuration file, which allows local users to obtain user credentials by reading the file.
EPSS
2.1 Low
CVSS2