CVE-2013-1921: Red Hat JBoss Enterprise Application Platform

Low severity, CVSS 1.9. EPSS: 0.2% chance of exploitation in the next 30 days.

PicketBox, as used in Red Hat JBoss Enterprise Application Platform before 6.1.1, allows local users to obtain the admin encryption key by reading the Vault data file.

Affected products

  • Red Hat JBoss Enterprise Application Platform: up to and including 6.1.0; version 4.2.0 only; version 4.3.0 only; version 5.0.0 only; version 5.0.1 only; version 5.1.0 only; …

Published 2013-09-28. Last modified 2026-06-16.