Vulnerabilities > Redhat > Jboss Enterprise Brms Platform > Low

DATE CVE VULNERABILITY TITLE RISK
2015-02-20 CVE-2014-0005 Permissions, Privileges, and Access Controls vulnerability in Redhat products
PicketBox and JBossSX, as used in Red Hat JBoss Enterprise Application Platform (JBEAP) 6.2.2 and JBoss BRMS before 6.0.3 roll up patch 2, allows remote authenticated users to read and modify the application sever configuration and state by deploying a crafted application.
local
low complexity
redhat CWE-264
3.6
2013-02-05 CVE-2012-0034 Credentials Management vulnerability in Redhat products
The NonManagedConnectionFactory in JBoss Enterprise Application Platform (EAP) 5.1.2 and 5.2.0, Web Platform (EWP) 5.1.2 and 5.2.0, and BRMS Platform before 5.3.1 logs the username and password in cleartext when an exception is thrown, which allows local users to obtain sensitive information by reading the log file.
local
low complexity
redhat CWE-255
2.1
2012-11-23 CVE-2012-2377 Improper Authentication vulnerability in Redhat products
JGroups diagnostics service in JBoss Enterprise Portal Platform before 5.2.2, SOA Platform before 5.3.0, and BRMS Platform before 5.3.0, is enabled without authentication when started by the JGroups channel, which allows remote attackers in adjacent networks to read diagnostics information via a crafted IP multicast.
low complexity
redhat CWE-287
3.3