PicketBox, as used in Red Hat JBoss Enterprise Application Platform before 6.1.1, allows local users to obtain the admin encryption key by reading the Vault data file.
| Software | From | Fixed in |
|---|---|---|
| redhat / jboss_enterprise_application_platform | 6.0.1 | 6.0.1.x |
| redhat / jboss_enterprise_application_platform | 5.1.2 | 5.1.2.x |
| redhat / jboss_enterprise_application_platform | 4.3.0 | 4.3.0.x |
| redhat / jboss_enterprise_application_platform | 6.0.0 | 6.0.0.x |
| redhat / jboss_enterprise_application_platform | 5.2.2 | 5.2.2.x |
| redhat / jboss_enterprise_application_platform | 5.1.1 | 5.1.1.x |
| redhat / jboss_enterprise_application_platform | 5.0.1 | 5.0.1.x |
| redhat / jboss_enterprise_application_platform | - | 6.1.0.x |
| redhat / jboss_enterprise_application_platform | 5.1.0 | 5.1.0.x |
| redhat / jboss_enterprise_application_platform | 5.2.0 | 5.2.0.x |
| redhat / jboss_enterprise_application_platform | 5.2.1 | 5.2.1.x |
| redhat / jboss_enterprise_application_platform | 4.2.0 | 4.2.0.x |
| redhat / jboss_enterprise_application_platform | 5.0.0 | 5.0.0.x |