CVE-2013-4452

Impact:
Moderate
Public Date:
2013-11-25
Bugzilla:
1021756: CVE-2013-4452 JBoss ON: World readable configuration files expose sensitive data

The MITRE CVE dictionary describes this issue as:

Red Hat JBoss Operations Network 3.1.2 uses world-readable permissions for the (1) server and (2) agent configuration files, which allows local users to obtain authentication credentials and other unspecified sensitive information by reading these files.

Find out more about CVE-2013-4452 from the MITRE CVE dictionary dictionary and NIST NVD.

CVSS v2 metrics

Base Score 2.1
Base Metrics AV:L/AC:L/Au:N/C:P/I:N/A:N
Access Vector Local
Access Complexity Low
Authentication None
Confidentiality Impact Partial
Integrity Impact None
Availability Impact None

Find out more about Red Hat support for the Common Vulnerability Scoring System (CVSS).

Red Hat Security Errata

Platform Errata Release Date
Red Hat JBoss Operations Network 3.1 RHSA-2013:1762 2013-11-25

Acknowledgements

This issue was discovered by Larry O'Leary of the Red Hat Middleware Support Engineering Group.

Last Modified

CVE description copyright © 2017, The MITRE Corporation

Close

Welcome! Check out the Getting Started with Red Hat page for quick tours and guides for common tasks.