On the JBoss EAP 5 EC2 AMI, the /var/cache/jboss-ec2-eap directory has default permissions of 755. A local attacker could exploit these insecure permissions to read potentially sensitive information from this directory, such as AWS credentials.
Acknowledgements: This issue was discovered by Aleksandar Kostadinov of the Red Hat QE Team.
This issue has been addressed in following products: JBEAP 5 for RHEL 6 Via RHSA-2012:1376 https://rhn.redhat.com/errata/RHSA-2012-1376.html