First published: Tue Jan 10 2012(Updated: )
It was found that the NonManagedConnectionFactory would log the username and password in cleartext when an exception was thrown. A local attacker could exploit this flaw by reading the password from the log file, if they had appropriate permissions to read the log file.
Credit: secalert@redhat.com
Affected Software | Affected Version | How to fix |
---|---|---|
Redhat Jboss Enterprise Application Platform | =5.1.2 | |
Redhat Jboss Enterprise Application Platform | =5.2.0 | |
Redhat Jboss Enterprise Web Platform | =5.1.2 | |
Redhat Jboss Enterprise Web Platform | =5.2.0 | |
Redhat Jboss Enterprise Brms Platform | <=5.3.0 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.