First published: Tue Aug 05 2014(Updated: )
It was identified that the Command Line Interface, as provided by Red Hat Enterprise Application Platform and WildFly (previously JBoss Application Server), created a history file named .jboss-cli-history in the user's home directory with insecure default file permissions. This could allow a malicious local user to gain information otherwise not accessible.
Credit: secalert@redhat.com
Affected Software | Affected Version | How to fix |
---|---|---|
Red Hat JBoss Enterprise Application Platform | <=6.3.3 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2014-3586 is classified as a medium severity vulnerability due to its potential to expose sensitive information.
To fix CVE-2014-3586, update Red Hat Enterprise Application Platform or WildFly to a version that resolves the insecure file permission issue.
CVE-2014-3586 may allow unauthorized users to access command history that contains sensitive information, compromising user privacy.
CVE-2014-3586 affects versions of Red Hat JBoss Enterprise Application Platform up to and including 6.3.3.
Yes, Red Hat has released patches in subsequent updates to address the vulnerabilities associated with CVE-2014-3586.