CVE-2012-0034

The NonManagedConnectionFactory in JBoss Enterprise Application Platform (EAP) 5.1.2 and 5.2.0, Web Platform (EWP) 5.1.2 and 5.2.0, and BRMS Platform before 5.3.1 logs the username and password in cleartext when an exception is thrown, which allows local users to obtain sensitive information by reading the log file.
References
Link Resource
http://rhn.redhat.com/errata/RHSA-2012-0108.html Vendor Advisory
http://rhn.redhat.com/errata/RHSA-2012-1072.html
http://rhn.redhat.com/errata/RHSA-2013-0191.html
http://rhn.redhat.com/errata/RHSA-2013-0192.html Vendor Advisory
http://rhn.redhat.com/errata/RHSA-2013-0193.html
http://rhn.redhat.com/errata/RHSA-2013-0195.html Vendor Advisory
http://rhn.redhat.com/errata/RHSA-2013-0196.html Vendor Advisory
http://rhn.redhat.com/errata/RHSA-2013-0197.html Vendor Advisory
http://rhn.redhat.com/errata/RHSA-2013-0221.html
http://rhn.redhat.com/errata/RHSA-2013-0533.html
http://secunia.com/advisories/51984 Vendor Advisory
http://secunia.com/advisories/52054 Vendor Advisory
http://www.osvdb.org/78259
http://www.securityfocus.com/bid/51392
https://bugzilla.redhat.com/show_bug.cgi?id=772835
https://issues.jboss.org/browse/JBCACHE-1612
http://rhn.redhat.com/errata/RHSA-2012-0108.html Vendor Advisory
http://rhn.redhat.com/errata/RHSA-2012-1072.html
http://rhn.redhat.com/errata/RHSA-2013-0191.html
http://rhn.redhat.com/errata/RHSA-2013-0192.html Vendor Advisory
http://rhn.redhat.com/errata/RHSA-2013-0193.html
http://rhn.redhat.com/errata/RHSA-2013-0195.html Vendor Advisory
http://rhn.redhat.com/errata/RHSA-2013-0196.html Vendor Advisory
http://rhn.redhat.com/errata/RHSA-2013-0197.html Vendor Advisory
http://rhn.redhat.com/errata/RHSA-2013-0221.html
http://rhn.redhat.com/errata/RHSA-2013-0533.html
http://secunia.com/advisories/51984 Vendor Advisory
http://secunia.com/advisories/52054 Vendor Advisory
http://www.osvdb.org/78259
http://www.securityfocus.com/bid/51392
https://bugzilla.redhat.com/show_bug.cgi?id=772835
https://issues.jboss.org/browse/JBCACHE-1612
Configurations

Configuration 1 (hide)

OR cpe:2.3:a:redhat:jboss_enterprise_application_platform:5.1.2:*:*:*:*:*:*:*
cpe:2.3:a:redhat:jboss_enterprise_application_platform:5.2.0:*:*:*:*:*:*:*

Configuration 2 (hide)

OR cpe:2.3:a:redhat:jboss_enterprise_web_platform:5.1.2:*:*:*:*:*:*:*
cpe:2.3:a:redhat:jboss_enterprise_web_platform:5.2.0:*:*:*:*:*:*:*

Configuration 3 (hide)

cpe:2.3:a:redhat:jboss_enterprise_brms_platform:*:*:*:*:*:*:*:*

History

21 Nov 2024, 01:34

Type Values Removed Values Added
References () http://rhn.redhat.com/errata/RHSA-2012-0108.html - Vendor Advisory () http://rhn.redhat.com/errata/RHSA-2012-0108.html - Vendor Advisory
References () http://rhn.redhat.com/errata/RHSA-2012-1072.html - () http://rhn.redhat.com/errata/RHSA-2012-1072.html -
References () http://rhn.redhat.com/errata/RHSA-2013-0191.html - () http://rhn.redhat.com/errata/RHSA-2013-0191.html -
References () http://rhn.redhat.com/errata/RHSA-2013-0192.html - Vendor Advisory () http://rhn.redhat.com/errata/RHSA-2013-0192.html - Vendor Advisory
References () http://rhn.redhat.com/errata/RHSA-2013-0193.html - () http://rhn.redhat.com/errata/RHSA-2013-0193.html -
References () http://rhn.redhat.com/errata/RHSA-2013-0195.html - Vendor Advisory () http://rhn.redhat.com/errata/RHSA-2013-0195.html - Vendor Advisory
References () http://rhn.redhat.com/errata/RHSA-2013-0196.html - Vendor Advisory () http://rhn.redhat.com/errata/RHSA-2013-0196.html - Vendor Advisory
References () http://rhn.redhat.com/errata/RHSA-2013-0197.html - Vendor Advisory () http://rhn.redhat.com/errata/RHSA-2013-0197.html - Vendor Advisory
References () http://rhn.redhat.com/errata/RHSA-2013-0221.html - () http://rhn.redhat.com/errata/RHSA-2013-0221.html -
References () http://rhn.redhat.com/errata/RHSA-2013-0533.html - () http://rhn.redhat.com/errata/RHSA-2013-0533.html -
References () http://secunia.com/advisories/51984 - Vendor Advisory () http://secunia.com/advisories/51984 - Vendor Advisory
References () http://secunia.com/advisories/52054 - Vendor Advisory () http://secunia.com/advisories/52054 - Vendor Advisory
References () http://www.osvdb.org/78259 - () http://www.osvdb.org/78259 -
References () http://www.securityfocus.com/bid/51392 - () http://www.securityfocus.com/bid/51392 -
References () https://bugzilla.redhat.com/show_bug.cgi?id=772835 - () https://bugzilla.redhat.com/show_bug.cgi?id=772835 -
References () https://issues.jboss.org/browse/JBCACHE-1612 - () https://issues.jboss.org/browse/JBCACHE-1612 -

Information

Published : 2013-02-05 23:55

Updated : 2024-11-21 01:34


NVD link : CVE-2012-0034

Mitre link : CVE-2012-0034

CVE.ORG link : CVE-2012-0034


JSON object : View

Products Affected

redhat

  • jboss_enterprise_application_platform
  • jboss_enterprise_web_platform
  • jboss_enterprise_brms_platform
CWE
CWE-255

Credentials Management Errors