CVE-2014-3586
Red Hat JBoss Enterprise Application Platform < 6.3.3 - Information Disclosure via Weak .jboss-cli-history Permissions
Title source: llmDescription
The default configuration for the Command Line Interface in Red Hat Enterprise Application Platform before 6.4.0 and WildFly (formerly JBoss Application Server) uses weak permissions for .jboss-cli-history, which allows local users to obtain sensitive information via unspecified vectors.
References (6)
Core 6
Core References
Vendor Advisory vendor-advisory
x_refsource_redhat
http://rhn.redhat.com/errata/RHSA-2015-0846.html
Vendor Advisory vendor-advisory
x_refsource_redhat
http://rhn.redhat.com/errata/RHSA-2015-0849.html
Vendor Advisory vendor-advisory
x_refsource_redhat
http://rhn.redhat.com/errata/RHSA-2015-0848.html
Vendor Advisory vendor-advisory
x_refsource_redhat
http://rhn.redhat.com/errata/RHSA-2015-0847.html
Third Party Advisory, VDB Entry vdb-entry
x_refsource_sectrack
http://www.securitytracker.com/id/1032183
Issue Tracking x_refsource_confirm
https://bugzilla.redhat.com/show_bug.cgi?id=1126687
Scores
EPSS
0.0037
EPSS Percentile
29.7%
Details
CWE
CWE-264
Status
published
Products (1)
redhat/jboss_enterprise_application_platform
< 6.3.3
Published
Apr 21, 2015
Tracked Since
Feb 18, 2026