OSVDB ID: 86409

Title: JBoss Enterprise Application Platform /var/cache/jboss-ec2-eap Permission Weakness Local Information Disclosure

Info

Disclosure

Oct 16, 2012

Discovery

Unknown

Dates

Exploit

Unknown

Solution

Oct 16, 2012

Description

JBoss Enterprise Application Platform contains a flaw that may lead to an unauthorized information disclosure. The issue is triggered when the application sets insecure world-readable permissions on the /var/cache/jboss-ec2-eap directory. This may allow a local attacker to gain access to potentially sensitive Amazon Web Service (AWS) credentials.

Classification

Location: Local Access Required
Attack Type: Information Disclosure
Impact: Loss of Confidentiality
Solution: Patch / RCS
Exploit: Exploit Public
Disclosure: Vendor Verified
OSVDB: Authentication Required

Solution

The vendor has released a patch to address this vulnerability. Check the vendor advisory or solution in the references section. There are no known workarounds or upgrades to correct this issue.

Products

Red Hat, Inc.

JBoss Enterprise Application Platform

5 EL6

References

Credit

Unknown or Incomplete



Direct URL: http://osvdb.org/86409