CVE-2021-3425

A flaw was found in the AMQ Broker that discloses JDBC encrypted usernames and passwords when provided in the AMQ Broker application logfile when using the jdbc persistence functionality. Versions shipped in Red Hat AMQ 7 are vulnerable.
References
Link Resource
https://bugzilla.redhat.com/show_bug.cgi?id=1936629 Issue Tracking Vendor Advisory
Configurations

Configuration 1 (hide)

cpe:2.3:a:redhat:jboss_a-mq:7:*:*:*:*:*:*:*

History

11 Jun 2021, 15:18

Type Values Removed Values Added
CWE CWE-532
CPE cpe:2.3:a:redhat:jboss_a-mq:7:*:*:*:*:*:*:*
CVSS v2 : unknown
v3 : unknown
v2 : 2.1
v3 : 4.4
References (MISC) https://bugzilla.redhat.com/show_bug.cgi?id=1936629 - (MISC) https://bugzilla.redhat.com/show_bug.cgi?id=1936629 - Issue Tracking, Vendor Advisory

01 Jun 2021, 20:15

Type Values Removed Values Added
New CVE

Information

Published : 2021-06-01 20:15

Updated : 2023-12-10 13:55


NVD link : CVE-2021-3425

Mitre link : CVE-2021-3425

CVE.ORG link : CVE-2021-3425


JSON object : View

Products Affected

redhat

  • jboss_a-mq
CWE
CWE-532

Insertion of Sensitive Information into Log File