CVE-2014-0058

The security audit functionality in Red Hat JBoss Enterprise Application Platform (EAP) 6.x before 6.2.1 logs request parameters in plaintext, which might allow local users to obtain passwords by reading the log files.
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTNIST
1.9 UNKNOWN
LOCAL
MEDIUM
AV:L/AC:M/Au:N/C:P/I:N/A:N
redhatCNA
---
---
CVEADP
---
---
Base Score
CVSS 3.x
EPSS Score
Percentile: 19%
VendorProductVersion
redhatjboss_enterprise_application_platform
6.0.0
redhatjboss_enterprise_application_platform
6.0.1
redhatjboss_enterprise_application_platform
6.1.0
redhatjboss_enterprise_application_platform
6.2.0
𝑥
= Vulnerable software versions
Common Weakness Enumeration