CVE Database
/

CVE-2012-0034

Back to search

CVE-2012-0034

Published: Feb 5, 2013

Modified: Aug 6, 2024

PUBLISHED

Description

The NonManagedConnectionFactory in JBoss Enterprise Application Platform (EAP) 5.1.2 and 5.2.0, Web Platform (EWP) 5.1.2 and 5.2.0, and BRMS Platform before 5.3.1 logs the username and password in cleartext when an exception is thrown, which allows local users to obtain sensitive information by reading the log file.

VendorProductVersions

n/a

n/a

affected
n/a

References

78259
vdb-entry
x_refsource_OSVDB
RHSA-2013:0192
vendor-advisory
x_refsource_REDHAT
RHSA-2013:0195
vendor-advisory
x_refsource_REDHAT
RHSA-2013:0221
vendor-advisory
x_refsource_REDHAT
RHSA-2013:0196
vendor-advisory
x_refsource_REDHAT
51392
vdb-entry
x_refsource_BID
RHSA-2012:1072
vendor-advisory
x_refsource_REDHAT
RHSA-2013:0193
vendor-advisory
x_refsource_REDHAT
RHSA-2012:0108
vendor-advisory
x_refsource_REDHAT
51984
third-party-advisory
x_refsource_SECUNIA
52054
third-party-advisory
x_refsource_SECUNIA
RHSA-2013:0191
vendor-advisory
x_refsource_REDHAT
RHSA-2013:0533
vendor-advisory
x_refsource_REDHAT
RHSA-2013:0197
vendor-advisory
x_refsource_REDHAT

Security Training

Train your team to recognize and prevent security threats with our comprehensive security awareness program.

Start Training

Vulnerability Scanning

Discover vulnerabilities in your applications and infrastructure before attackers do.

Scan Now