Security Advisory
CVE-2016-7061
CVE vulnerability detail — eXtreme Datacenter Security Operations
Description
An information disclosure vulnerability was found in JBoss Enterprise Application Platform before 7.0.4. It was discovered that when configuring RBAC and marking information as sensitive, users with a Monitor role are able to view the sensitive information.