CVE-2012-3427: Low severity redhat JBoss Enterprise Application Platform vulnerability
Published Feb 2, 2014
·Updated
EC2 Amazon Machine Image (AMI) in JBoss Enterprise Application Platform (EAP) 5.1.2 uses 755 permissions for /var/cache/jboss-ec2-eap/, which allows local users to read sensitive information such as Amazon Web Services (AWS) credentials by reading files in the directory.
Affected Software
1 affected component
redhat JBoss Enterprise Application Platform=5.1.2
Event History
Feb 2, 2014
CVE Published
via MITRE·08:00 PM
Data Sourced
via MITRE·08:00 PM
Description
Frequently Asked Questions
1
What is the severity of CVE-2012-3427?
CVE-2012-3427 is considered to have a medium severity due to the potential exposure of sensitive AWS credentials.
2
How do I fix CVE-2012-3427?
To fix CVE-2012-3427, change the permissions for /var/cache/jboss-ec2-eap/ to restrict access, preferably to 700.
3
Who is affected by CVE-2012-3427?
CVE-2012-3427 affects users running JBoss Enterprise Application Platform version 5.1.2.
4
What are the risks associated with CVE-2012-3427?
The risks associated with CVE-2012-3427 include unauthorized access to AWS credentials by local users.
5
When was CVE-2012-3427 published?
CVE-2012-3427 was published on July 19, 2012.