CVE-2014-3586: Red Hat JBoss Enterprise Application Platform

Low severity, CVSS 2.1. EPSS: 0.4% chance of exploitation in the next 30 days.

The default configuration for the Command Line Interface in Red Hat Enterprise Application Platform before 6.4.0 and WildFly (formerly JBoss Application Server) uses weak permissions for .jboss-cli-history, which allows local users to obtain sensitive information via unspecified vectors.

Affected products

  • Red Hat JBoss Enterprise Application Platform: up to and including 6.3.3

Published 2015-04-21. Last modified 2026-06-17.