VulnerabilityModified
CVE-2013-4452
Red Hat JBoss Operations Network 3.1.2 uses world-readable permissions for the (1) server and (2) agent configuration files, which allows local users to obtain authentication credentials and other unspecified sensitive information by reading these files.
LOW 2.1EPSS 0.36%
Does this matter?
Lower severity and a low EPSS score (0.36%). Track it; it rarely justifies an emergency change on its own.
Description
Red Hat JBoss Operations Network 3.1.2 uses world-readable permissions for the (1) server and (2) agent configuration files, which allows local users to obtain authentication credentials and other unspecified sensitive information by reading these files.
- CVSS 2.0
- 2.1 LOWAV:L/AC:L/Au:N/C:P/I:N/A:N
- EPSS
- 0.36% probability · 30th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-264
- Affected
- redhat/jboss operations network
- Source
- secalert@redhat.com
References
- http://rhn.redhat.com/errata/RHSA-2013-1762.htmlVendor Advisory
- http://secunia.com/advisories/55852Vendor Advisory
- http://www.securityfocus.com/bid/63916
- http://www.securitytracker.com/id/1029390
- http://rhn.redhat.com/errata/RHSA-2013-1762.htmlVendor Advisory
- http://secunia.com/advisories/55852Vendor Advisory
- http://www.securityfocus.com/bid/63916
- http://www.securitytracker.com/id/1029390
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.