CVE-2012-0034
Cache: NonManagedConnectionFactory will log password in clear text when an exception occurs
Severity Score
Exploit Likelihood
Affected Versions
Public Exploits
0Exploited in Wild
-Decision
Descriptions
The NonManagedConnectionFactory in JBoss Enterprise Application Platform (EAP) 5.1.2 and 5.2.0, Web Platform (EWP) 5.1.2 and 5.2.0, and BRMS Platform before 5.3.1 logs the username and password in cleartext when an exception is thrown, which allows local users to obtain sensitive information by reading the log file.
El NonManagedConnectionFactory en JBoss Enterprise Application Platform (EAP) v5.1.2 y v5.2.0, Web Platform (EWP) v5.1.2 y v5.2.0, y BRMS Platform anterior a v5.3.1 guarda el nombre de usuario y el password en texto plano cuando una excepción es lanzada, lo que permite a usuarios locales obtener información sensible mediante la lectura de un fichero de log.
An attack technique against the W3C XML Encryption Standard when block ciphers were used in CBC mode could allow a remote attacker to conduct chosen-ciphertext attacks, leading to the recovery of the entire plain text of a particular cryptogram. JBoss Web Services leaked side-channel data when distributing symmetric keys, allowing a remote attacker to recover the entire plain text form of a symmetric key. Spring framework could possibly evaluate Expression Language expressions twice, allowing a remote attacker to execute arbitrary code in the context of the application server, or to obtain sensitive information from the server. Manual action is required to apply this fix.
CVSS Scores
SSVC
- Decision:-
Timeline
- 2011-12-07 CVE Reserved
- 2012-02-10 CVE Published
- 2024-08-06 CVE Updated
- 2025-03-30 EPSS Updated
- ---------- Exploited in Wild
- ---------- KEV Due Date
- ---------- First Exploit
CWE
- CWE-255: Credentials Management Errors
CAPEC
References (17)
URL | Tag | Source |
---|---|---|
http://www.osvdb.org/78259 | Vdb Entry | |
http://www.securityfocus.com/bid/51392 | Vdb Entry | |
https://issues.jboss.org/browse/JBCACHE-1612 | X_refsource_confirm |
URL | Date | SRC |
---|
URL | Date | SRC |
---|
URL | Date | SRC |
---|---|---|
http://rhn.redhat.com/errata/RHSA-2012-0108.html | 2015-01-18 | |
http://rhn.redhat.com/errata/RHSA-2012-1072.html | 2015-01-18 | |
http://rhn.redhat.com/errata/RHSA-2013-0191.html | 2015-01-18 | |
http://rhn.redhat.com/errata/RHSA-2013-0192.html | 2015-01-18 | |
http://rhn.redhat.com/errata/RHSA-2013-0193.html | 2015-01-18 | |
http://rhn.redhat.com/errata/RHSA-2013-0195.html | 2015-01-18 | |
http://rhn.redhat.com/errata/RHSA-2013-0196.html | 2015-01-18 | |
http://rhn.redhat.com/errata/RHSA-2013-0197.html | 2015-01-18 | |
http://rhn.redhat.com/errata/RHSA-2013-0221.html | 2015-01-18 | |
http://rhn.redhat.com/errata/RHSA-2013-0533.html | 2015-01-18 | |
http://secunia.com/advisories/51984 | 2015-01-18 | |
http://secunia.com/advisories/52054 | 2015-01-18 | |
https://bugzilla.redhat.com/show_bug.cgi?id=772835 | 2013-02-20 | |
https://access.redhat.com/security/cve/CVE-2012-0034 | 2013-02-20 |
Affected Vendors, Products, and Versions
Vendor | Product | Version | Other | Status | ||||||
---|---|---|---|---|---|---|---|---|---|---|
Vendor | Product | Version | Other | Status | <-- --> | Vendor | Product | Version | Other | Status |
Redhat Search vendor "Redhat" | Jboss Enterprise Application Platform Search vendor "Redhat" for product "Jboss Enterprise Application Platform" | 5.1.2 Search vendor "Redhat" for product "Jboss Enterprise Application Platform" and version "5.1.2" | - |
Affected
| ||||||
Redhat Search vendor "Redhat" | Jboss Enterprise Application Platform Search vendor "Redhat" for product "Jboss Enterprise Application Platform" | 5.2.0 Search vendor "Redhat" for product "Jboss Enterprise Application Platform" and version "5.2.0" | - |
Affected
| ||||||
Redhat Search vendor "Redhat" | Jboss Enterprise Web Platform Search vendor "Redhat" for product "Jboss Enterprise Web Platform" | 5.1.2 Search vendor "Redhat" for product "Jboss Enterprise Web Platform" and version "5.1.2" | - |
Affected
| ||||||
Redhat Search vendor "Redhat" | Jboss Enterprise Web Platform Search vendor "Redhat" for product "Jboss Enterprise Web Platform" | 5.2.0 Search vendor "Redhat" for product "Jboss Enterprise Web Platform" and version "5.2.0" | - |
Affected
| ||||||
Redhat Search vendor "Redhat" | Jboss Enterprise Brms Platform Search vendor "Redhat" for product "Jboss Enterprise Brms Platform" | <= 5.3.0 Search vendor "Redhat" for product "Jboss Enterprise Brms Platform" and version " <= 5.3.0" | - |
Affected
|