JBoss Enterprise Application Platform and JBoss Enterprise Web Platform contain a flaw that may lead to unauthorized disclosure of potentially sensitive information. This issue is due to the SecurityAssociation.getCredential() function returning previous credentials if no security context is provided. This may allow a remote attacker to gain access to previous session credentials.