DescriptionArun Babu Neelicattu
2013-01-23 05:02:05 UTC
The JBoss EAP/EWP 5.2.0 GUI installer can generate an auto-install XML file that contains the admin/sucker password in plain text. This file when saved on disk is set as being world-readable. This means any local user can view the password which could then be used to gain administrator access to an EAP/EWP instance.