If a user exposes Remote JMX on EAP 5, or SOA-P 5 they could be vulnerable to a Denial of Service Attack.
It was identified that the Command Line Interface, as provided by Red Hat Enterprise Application Platform and WildFly (previously JBoss Application Server), created a history file named .jboss-cli-history in the user's home directory with insecure default file permissions. This could allow a malicious local user to gain information otherwise not accessible.
The JBoss EAP/EWP 5.2.0 GUI installer can generate an auto-install XML file that contains the admin/sucker password in plain text. This file when saved on disk is set as being world-readable. This means any local user can view the password which could then be used to gain administrator access to an EAP/EWP instance.
The JBoss EAP 430CP09 security updates for Red Hat Enterprise Linux 4, Red Hat Enterprise Linux 5 and the Customer Support Portal did not, unlike the erratum text stated, provide a fix for CVE-2010-3862, a Denial-of-Service (DoS) flaw in the jboss-remoting component. A missing patch is considered a security regression, and requires a new CVE name. This regression is assigned CVE-2010-4265. It fixes the same issue as CVE-2010-3862 and is specific to JBoss EAP 430CP09.