JBoss Enterprise Application Platform contains a flaw that may lead to an unauthorized information disclosure. The issue is triggered when the application sets insecure world-readable permissions on the /var/cache/jboss-ec2-eap directory. This may allow a local attacker to gain access to potentially sensitive Amazon Web Service (AWS) credentials.
Classification
Location:
Local Access Required
Attack Type:
Information Disclosure
Impact:
Loss of Confidentiality
Solution:
Patch / RCS
Exploit:
Exploit Public
Disclosure:
Vendor Verified
OSVDB:
Authentication Required
Solution
The vendor has released a patch to address this vulnerability. Check the vendor advisory or solution in the references section. There are no known workarounds or upgrades to correct this issue.