CVE-2013-0218: Infoleak
The GUI installer in JBoss Enterprise Application Platform (EAP) and Enterprise Web Platform (EWP) 5.2.0 and possibly 5.1.2 uses world-readable permissions for the auto-install XML file, which allows local users to obtain the administrator password and the sucker password by reading this file.
Other sources
The JBoss EAP/EWP 5.2.0 GUI installer can generate an auto-install XML file that contains the admin/sucker password in plain text. This file when saved on disk is set as being world-readable. This means any local user can view the password which could then be used to gain administrator access to an EAP/EWP instance.
— Red Hat
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2013-0218?
CVE-2013-0218 is classified as a moderate severity vulnerability.
How do I fix CVE-2013-0218?
To fix CVE-2013-0218, you should restrict the permissions of the auto-install XML file to prevent unauthorized access.
Which versions of JBoss are affected by CVE-2013-0218?
CVE-2013-0218 affects JBoss Enterprise Application Platform versions 5.1.2 and 5.2.0, as well as JBoss Enterprise Web Platform versions 5.1.2 and 5.2.0.
What attack vector does CVE-2013-0218 exploit?
CVE-2013-0218 can be exploited by local users who gain access to the world-readable auto-install XML file.
What sensitive information is exposed in CVE-2013-0218?
CVE-2013-0218 exposes the administrator password and sucker password contained in the auto-install XML file.