JBoss SX and PicketBox, as used in Red Hat JBoss Enterprise Application Platform (EAP) before 6.2.3, use world-readable permissions on audit.log, which allows local users to obtain sensitive information by reading this file.Referenceshttp://rhn.redhat.com/errata/RHSA-2014-0565.htmlhttp://rhn.redhat.com/errata/RHSA-2015-0675.htmlhttp://rhn.redhat.com/errata/RHSA-2015-0850.htmlhttp://rhn.redhat.com/errata/RHSA-2014-0563.htmlhttp://rhn.redhat.com/errata/RHSA-2015-0851.htmlhttp://rhn.redhat.com/errata/RHSA-2014-0564.html