Lucene search

K
veracodeVeracode Vulnerability DatabaseVERACODE:10773
HistoryJan 15, 2019 - 8:52 a.m.

Information Disclosure

2019-01-1508:52:04
Veracode Vulnerability Database
sca.analysiscenter.veracode.com
7

0.0004 Low

EPSS

Percentile

5.1%

JBoss SX and PicketBox is vulnerable to information disclosure. The audit.log file which stores logs containing confidential information is world-readable. This allows a local user to read the log file and obtain sensitive information such as usernames and passwords.

References

0.0004 Low

EPSS

Percentile

5.1%

Related for VERACODE:10773