JBoss Enterprise Application Platform / JBoss Enterprise Web Platform Insecure Auto-install XML File Admin Password Local Disclosure Vulnerability
29 Apr. 2013
Summary
JBoss enterprise application platform / jboss enterprise web platform insecure auto-install xml file admin password local suffers from disclosure vulnerability
Credit:
The information has been provided by Arun Neelicattu - Red Hat Security Response Team .
Vulnerable Systems:
*Red Hat, Inc. JBoss Enterprise Application Platform 5.2.0
*Red Hat, Inc JBoss Enterprise Web Platform 5.2.0
JBoss Enterprise Application Platform and JBoss Enterprise Web Platform contain a flaw that may lead to unauthorized disclosure of potentially sensitive information. The issue is due to the program creating an insecure world readable auto-install XML file that contains sensitive information. This may allow a local attacker to gain access to administrative password information.