Description
PicketBox, as used in Red Hat JBoss Enterprise Application Platform before 6.1.1, allows local users to obtain the admin encryption key by reading the Vault data file.
Remediation
References
http://rhn.redhat.com/errata/RHSA-2013-1207.html
http://rhn.redhat.com/errata/RHSA-2013-1208.html
http://rhn.redhat.com/errata/RHSA-2013-1209.html
http://rhn.redhat.com/errata/RHSA-2013-1437.html
http://rhn.redhat.com/errata/RHSA-2014-0029.html
https://bugzilla.redhat.com/show_bug.cgi?id=948106
Related Vulnerabilities
CVE-2022-33140 Vulnerability in maven package org.apache.nifi.registry:nifi-registry-core
CVE-2021-45105 Vulnerability in maven package org.apache.logging.log4j:log4j-core
CVE-2023-4853 Vulnerability in maven package io.quarkus:quarkus-vertx-http
CVE-2019-10306 Vulnerability in maven package org.jenkins-ci.plugins:ontrack
CVE-2022-25312 Vulnerability in maven package org.apache.any23:apache-any23