Vulnerabilities > Redhat > Jboss Enterprise WEB Platform > Low

DATE CVE VULNERABILITY TITLE RISK
2013-02-05 CVE-2012-0034 Credentials Management vulnerability in Redhat products
The NonManagedConnectionFactory in JBoss Enterprise Application Platform (EAP) 5.1.2 and 5.2.0, Web Platform (EWP) 5.1.2 and 5.2.0, and BRMS Platform before 5.3.1 logs the username and password in cleartext when an exception is thrown, which allows local users to obtain sensitive information by reading the log file.
local
low complexity
redhat CWE-255
2.1
2013-02-05 CVE-2013-0218 Information Exposure vulnerability in Redhat products
The GUI installer in JBoss Enterprise Application Platform (EAP) and Enterprise Web Platform (EWP) 5.2.0 and possibly 5.1.2 uses world-readable permissions for the auto-install XML file, which allows local users to obtain the administrator password and the sucker password by reading this file.
local
low complexity
redhat CWE-200
2.1
2010-12-30 CVE-2010-3862 Improper Input Validation vulnerability in Redhat products
The org.jboss.remoting.transport.bisocket.BisocketServerInvoker$SecondaryServerSocketThread.run method in JBoss Remoting 2.2.x before 2.2.3.SP4 and 2.5.x before 2.5.3.SP2 in Red Hat JBoss Enterprise Application Platform (aka JBoss EAP or JBEAP) 4.3 through 4.3.0.CP09, and 5.1.0; and JBoss Enterprise Web Platform (aka JBEWP) 5.1.0; allows remote attackers to cause a denial of service (daemon outage) by establishing a bisocket control connection TCP session, and then not sending any application data.
network
high complexity
redhat CWE-20
2.6