CVE-2013-0218: Red Hat JBoss Enterprise Application Platform
Low severity, CVSS 2.1. EPSS: 0.4% chance of exploitation in the next 30 days.
The GUI installer in JBoss Enterprise Application Platform (EAP) and Enterprise Web Platform (EWP) 5.2.0 and possibly 5.1.2 uses world-readable permissions for the auto-install XML file, which allows local users to obtain the administrator password and the sucker password by reading this file.
Affected products
- Red Hat JBoss Enterprise Application Platform: version 5.1.2 only; version 5.2.0 only
- Red Hat JBoss Enterprise Web Platform: version 5.1.2 only; version 5.2.0 only
Published 2013-02-05. Last modified 2026-06-16.