CVE-2014-0058

medium

Description

The security audit functionality in Red Hat JBoss Enterprise Application Platform (EAP) 6.x before 6.2.1 logs request parameters in plaintext, which might allow local users to obtain passwords by reading the log files.

References

http://www.securityfocus.com/bid/65762

http://rhn.redhat.com/errata/RHSA-2015-0034.html

http://rhn.redhat.com/errata/RHSA-2014-0205.html

http://rhn.redhat.com/errata/RHSA-2014-0204.html

Details

Source: Mitre, NVD

Published: 2014-02-26

Updated: 2017-01-07

Risk Information

CVSS v2

Base Score: 1.9

Vector: CVSS2#AV:L/AC:M/Au:N/C:P/I:N/A:N

Severity: Low

CVSS v3

Base Score: 5.5

Vector: CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N

Severity: Medium