CVE-2013-1921 Information

Description

PicketBox as used in Red Hat JBoss Enterprise Application Platform before 6.1.1 allows local users to obtain the admin encryption key by reading the Vault data file.

Reference

http://rhn.redhat.com/errata/RHSA-2013-1207.html http://rhn.redhat.com/errata/RHSA-2013-1208.html http://rhn.redhat.com/errata/RHSA-2013-1209.html http://rhn.redhat.com/errata/RHSA-2013-1437.html http://rhn.redhat.com/errata/RHSA-2014-0029.html https://bugzilla.redhat.com/show_bug.cgi?id=948106

Share on: