"value":"A flaw was found in wildfly-core. A management user could use the resolve-expression in the HAL Interface to read possible sensitive information from the Wildfly system. This issue could allow a malicious user to access the system and obtain possible sensitive information from the system."
}
]
},
"problemtype":{
"problemtype_data":[
{
"description":[
{
"lang":"eng",
"value":"Exposure of Sensitive Information to an Unauthorized Actor",
"cweId":"CWE-200"
}
]
}
]
},
"affects":{
"vendor":{
"vendor_data":[
{
"vendor_name":"n/a",
"product":{
"product_data":[
{
"product_name":"wildfly-core",
"version":{
"version_data":[
{
"version_value":"not down converted",
"x_cve_json_5_version_data":{
"versions":[
{
"version":"15.0.30.Final",
"status":"unaffected"
}
]
}
}
]
}
}
]
}
},
{
"vendor_name":"Red Hat",
"product":{
"product_data":[
{
"product_name":"EAP 7.4.13",
"version":{
"version_data":[
{
"version_value":"not down converted",
"x_cve_json_5_version_data":{
"defaultStatus":"unaffected"
}
}
]
}
},
{
"product_name":"Red Hat JBoss Enterprise Application Platform 7.4 for RHEL 8",
"value":"Wildfly administrators are recommended to use Vault, especially the Elytron subsystem, to store potential critical information such as DNS, IPs, and credentials."