LOW
ON: World readable configuration files expose sensitive data
Published Dec 24, 2013
2.1
LOWCVSS 2.0
EPSS 0.36%
Description
Red Hat JBoss Operations Network 3.1.2 uses world-readable permissions for the (1) server and (2) agent configuration files, which allows local users to obtain authentication credentials and other unspecified sensitive information by reading these files.
Affected products
No data.
- 3.1.2
No data.
Red Hat JBoss Operations Network 3.1
n/a
Fixed · RHSA-2013:1762
Red Hat JBoss Operations Network 3
configuration
Affected
| Product | Package | State | Advisory |
|---|---|---|---|
| Red Hat JBoss Operations Network 3.1 | n/a | Fixed | RHSA-2013:1762 |
| Red Hat JBoss Operations Network 3 | configuration | Affected | n/a |
No package ranges for this CVE.
Remediation
No remediation recorded yet.
Weaknesses (1)
References (8)
- http://rhn.redhat.com/errata/RHSA-2013-1762.html vendor-advisoryx_refsource_REDHATVendor Advisory
- http://secunia.com/advisories/55852 third-party-advisoryx_refsource_SECUNIAVendor Advisory
- http://www.securityfocus.com/bid/63916 vdb-entryx_refsource_BID
- http://www.securitytracker.com/id/1029390 vdb-entryx_refsource_SECTRACK
- https://access.redhat.com/security/cve/CVE-2013-4452 Vendor Advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=1021756 Issue Tracking
- https://nvd.nist.gov/vuln/detail/CVE-2013-4452
- https://www.cve.org/CVERecord?id=CVE-2013-4452
| Link | Providers | Tags |
|---|---|---|
| http://rhn.redhat.com/errata/RHSA-2013-1762.html | vendor-advisoryx_refsource_REDHATVendor Advisory | |
| http://secunia.com/advisories/55852 | third-party-advisoryx_refsource_SECUNIAVendor Advisory | |
| http://www.securityfocus.com/bid/63916 | vdb-entryx_refsource_BID | |
| http://www.securitytracker.com/id/1029390 | vdb-entryx_refsource_SECTRACK | |
| https://access.redhat.com/security/cve/CVE-2013-4452 | Vendor Advisory | |
| https://bugzilla.redhat.com/show_bug.cgi?id=1021756 | Issue Tracking | |
| https://nvd.nist.gov/vuln/detail/CVE-2013-4452 | ||
| https://www.cve.org/CVERecord?id=CVE-2013-4452 |
Change history (0)
No recorded changes yet.
Sources
CVE.org / MITRE
Status PUBLISHED
Assigner redhat
Published Dec 24, 2013
Updated Aug 6, 2024
Reserved Jun 12, 2013
Link CVE-2013-4452
CISA Vulnrichment
Updated n/a