First published: Tue Aug 05 2014(Updated: )
It was identified that the Command Line Interface, as provided by Red Hat Enterprise Application Platform and WildFly (previously JBoss Application Server), created a history file named .jboss-cli-history in the user's home directory with insecure default file permissions. This could allow a malicious local user to gain information otherwise not accessible.
Affected Software | Affected Version | How to fix |
---|---|---|
Red Hat JBoss Enterprise Application Platform | ||
Red Hat WildFly and OpenSSL |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The severity of REDHAT-BUG-1126687 is considered moderate due to the potential for sensitive information to be exposed.
To fix REDHAT-BUG-1126687, change the permissions of the .jboss-cli-history file to ensure it is not readable by unauthorized users.
REDHAT-BUG-1126687 affects Red Hat Enterprise Application Platform and WildFly.
Mitigation strategies for REDHAT-BUG-1126687 include regularly reviewing file permissions and securing sensitive information.
Exploitation of REDHAT-BUG-1126687 could lead to unauthorized access to command historical data that may contain sensitive information.