First published: Sun Feb 02 2014(Updated: )
EC2 Amazon Machine Image (AMI) in JBoss Enterprise Application Platform (EAP) 5.1.2 uses 755 permissions for /var/cache/jboss-ec2-eap/, which allows local users to read sensitive information such as Amazon Web Services (AWS) credentials by reading files in the directory.
Credit: secalert@redhat.com
Affected Software | Affected Version | How to fix |
---|---|---|
JBoss Enterprise Application Platform | =5.1.2 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2012-3427 is considered to have a medium severity due to the potential exposure of sensitive AWS credentials.
To fix CVE-2012-3427, change the permissions for /var/cache/jboss-ec2-eap/ to restrict access, preferably to 700.
CVE-2012-3427 affects users running JBoss Enterprise Application Platform version 5.1.2.
The risks associated with CVE-2012-3427 include unauthorized access to AWS credentials by local users.
CVE-2012-3427 was published on July 19, 2012.