An information disclosure vulnerability was found in JBoss Enterprise Application Platform before 7.0.4. It was discovered that when configuring RBAC and marking information as sensitive, users with a Monitor role are able to view the sensitive information.
| Software | From | Fixed in |
|---|---|---|
| redhat / jboss_enterprise_application_platform | - | 7.0.4 |