CVE-2014-0058: Low severity redhat JBoss Enterprise Application Platform vulnerability
It was identified that web auditing, as provided by Red Hat JBoss Enterprise Application Platform 6, logged request parameters in plain text. This may include passwords used for authentication mechanisms such as BASIC and FORMAUTH. A local attacker, with access to audit logs, could compromise application/server credentials.
Other sources
The security audit functionality in Red Hat JBoss Enterprise Application Platform (EAP) 6.x before 6.2.1 logs request parameters in plaintext, which might allow local users to obtain passwords by reading the log files.
— MITRE
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2014-0058?
CVE-2014-0058 is considered a medium severity vulnerability due to the potential exposure of sensitive data in audit logs.
How do I fix CVE-2014-0058?
To fix CVE-2014-0058, upgrade to a patched version of Red Hat JBoss Enterprise Application Platform that addresses the logging of sensitive request parameters.
What versions are affected by CVE-2014-0058?
CVE-2014-0058 affects Red Hat JBoss Enterprise Application Platform versions 6.0.0, 6.0.1, 6.1.0, and 6.2.0.
What type of data could be compromised in CVE-2014-0058?
CVE-2014-0058 could result in the exposure of sensitive data, including passwords used for authentication mechanisms.
Who can exploit CVE-2014-0058?
A local attacker with access to the audit logs could exploit CVE-2014-0058 to compromise application accounts.