SB2013092803 - Cryptographic issues in JBoss Enterprise Application Platform
Published: September 28, 2013 Updated: August 10, 2020
Breakdown by Severity
- Low
- Medium
- High
- Critical
Description
This security bulletin contains information about 1 security vulnerability.
1) Cryptographic issues (CVE-ID: CVE-2013-1921)
The vulnerability allows a remote non-authenticated attacker to gain access to sensitive information.
PicketBox, as used in Red Hat JBoss Enterprise Application Platform before 6.1.1, allows local users to obtain the admin encryption key by reading the Vault data file.
Remediation
Install update from vendor's website.