CVE-2014-0058

EUVD-2014-0151
The security audit functionality in Red Hat JBoss Enterprise Application Platform (EAP) 6.x before 6.2.1 logs request parameters in plaintext, which might allow local users to obtain passwords by reading the log files.
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTPrimary
1.9 UNKNOWN
LOCAL
MEDIUM
AV:L/AC:M/Au:N/C:P/I:N/A:N
Base Score
CVSS 3.x
EPSS Score
Percentile: 18%
Affected Products (NVD)
VendorProductVersion
redhatjboss_enterprise_application_platform
6.0.0
redhatjboss_enterprise_application_platform
6.0.1
redhatjboss_enterprise_application_platform
6.1.0
redhatjboss_enterprise_application_platform
6.2.0
𝑥
= Vulnerable software versions
Common Weakness Enumeration