Bug 1770615 (CVE-2019-14885)

Summary: CVE-2019-14885 JBoss EAP: Vault system property security attribute value is revealed on CLI 'reload' command
Product: [Other] Security Response Reporter: Kunjan Rathod <krathod>
Component: vulnerabilityAssignee: Red Hat Product Security <security-response-team>
Status: CLOSED ERRATA QA Contact:
Severity: medium Docs Contact:
Priority: medium    
Version: unspecifiedCC: aboyko, asoldano, atangrin, bbaranow, bmaxwell, brian.stansberry, cdewolf, chazlett, darran.lofthouse, dkreling, dosoudil, drieden, iweiss, jawilson, jmesnil, jochrist, jperkins, jwon, krathod, kwills, lgao, msochure, msvehla, nwallace, padamec, pdrozd, pjindal, pmackay, psampaio, psotirop, rguimara, rsvoboda, security-response-team, smaestri, sthorger, tom.jenkinson, twalsh
Target Milestone: ---Keywords: Security
Target Release: ---   
Hardware: All   
OS: Linux   
Whiteboard:
Fixed In Version: JBoss EAP 7.2.6.GA Doc Type: If docs needed, set a value
Doc Text:
A flaw was found in the JBoss EAP Vault system. Confidential information of the system property’s security attribute value is revealed in the JBoss EAP log file when executing a JBoss CLI 'reload' command. This flaw can lead to the exposure of confidential information.
Story Points: ---
Clone Of: Environment:
Last Closed: 2020-01-21 08:10:05 UTC Type: ---
Regression: --- Mount Type: ---
Documentation: --- CRM:
Verified Versions: Category: ---
oVirt Team: --- RHEL 7.3 requirements from Atomic Host:
Cloudforms Team: --- Target Upstream Version:
Embargoed:
Bug Depends On: 1767088    
Bug Blocks: 1766523    

Description Kunjan Rathod 2019-11-11 00:22:12 UTC
It was found that the JBoss EAP Vault system property's security attribute value is revealed in the JBoss EAP's log file, when executing a JBoss CLI's 'reload' command which leads to exposing a confidential information.

Comment 5 errata-xmlrpc 2020-01-21 02:24:08 UTC
This issue has been addressed in the following products:

  Red Hat JBoss Enterprise Application Platform

Via RHSA-2020:0164 https://access.redhat.com/errata/RHSA-2020:0164

Comment 6 errata-xmlrpc 2020-01-21 02:56:40 UTC
This issue has been addressed in the following products:

  Red Hat JBoss Enterprise Application Platform 7.2 for RHEL 6

Via RHSA-2020:0159 https://access.redhat.com/errata/RHSA-2020:0159

Comment 7 errata-xmlrpc 2020-01-21 03:22:02 UTC
This issue has been addressed in the following products:

  Red Hat JBoss Enterprise Application Platform 7.2 for RHEL 8

Via RHSA-2020:0161 https://access.redhat.com/errata/RHSA-2020:0161

Comment 8 errata-xmlrpc 2020-01-21 03:46:50 UTC
This issue has been addressed in the following products:

  Red Hat JBoss Enterprise Application Platform 7.2 for RHEL 7

Via RHSA-2020:0160 https://access.redhat.com/errata/RHSA-2020:0160

Comment 9 Product Security DevOps Team 2020-01-21 08:10:05 UTC
This bug is now closed. Further updates for individual products will be reflected on the CVE page(s):

https://access.redhat.com/security/cve/cve-2019-14885

Comment 14 errata-xmlrpc 2020-03-23 20:13:52 UTC
This issue has been addressed in the following products:

  Red Hat Single Sign-On

Via RHSA-2020:0951 https://access.redhat.com/errata/RHSA-2020:0951

Comment 15 errata-xmlrpc 2020-05-14 11:46:36 UTC
This issue has been addressed in the following products:

  Red Hat JBoss Enterprise Application Platform 6.4 async

Via RHSA-2020:2168 https://access.redhat.com/errata/RHSA-2020:2168

Comment 16 errata-xmlrpc 2020-05-14 12:12:33 UTC
This issue has been addressed in the following products:

  Red Hat JBoss Enterprise Application Platform 6.4 for RHEL 5
  Red Hat JBoss Enterprise Application Platform 6.4 for RHEL 6
  Red Hat JBoss Enterprise Application Platform 6.4 for RHEL 7

Via RHSA-2020:2169 https://access.redhat.com/errata/RHSA-2020:2169

Comment 21 errata-xmlrpc 2020-07-01 10:53:08 UTC
This issue has been addressed in the following products:

  Red Hat JBoss Enterprise Application Platform 6.4 for RHEL 7

Via RHSA-2020:2780 https://access.redhat.com/errata/RHSA-2020:2780

Comment 22 errata-xmlrpc 2020-07-01 10:59:39 UTC
This issue has been addressed in the following products:

  Red Hat JBoss Enterprise Application Platform 6.4 for RHEL 5

Via RHSA-2020:2781 https://access.redhat.com/errata/RHSA-2020:2781

Comment 23 errata-xmlrpc 2020-07-01 11:08:04 UTC
This issue has been addressed in the following products:

  Red Hat JBoss Enterprise Application Platform 6.4 for RHEL 6

Via RHSA-2020:2779 https://access.redhat.com/errata/RHSA-2020:2779

Comment 24 errata-xmlrpc 2020-07-01 11:21:17 UTC
This issue has been addressed in the following products:

  Red Hat JBoss Enterprise Application Platform

Via RHSA-2020:2783 https://access.redhat.com/errata/RHSA-2020:2783