Lucene search

K
cve[email protected]CVE-2009-3554
HistoryDec 15, 2009 - 6:30 p.m.

CVE-2009-3554

2009-12-1518:30:01
CWE-200
web.nvd.nist.gov
23
cve
2009
3554
twiddle
red hat
jboss
eap
jbeap
jmx
sensitive information
local users
security vulnerability

2.1 Low

CVSS2

Attack Vector

LOCAL

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

PARTIAL

Integrity Impact

NONE

Availability Impact

NONE

AV:L/AC:L/Au:N/C:P/I:N/A:N

5.5 Medium

AI Score

Confidence

Low

0.0004 Low

EPSS

Percentile

5.1%

Twiddle in Red Hat JBoss Enterprise Application Platform (aka JBoss EAP or JBEAP) 4.2 before 4.2.0.CP08 and 4.3 before 4.3.0.CP07 writes the JMX password, and other command-line arguments, to the twiddle.log file, which allows local users to obtain sensitive information by reading this file.

Affected configurations

NVD
Node
redhatjboss_enterprise_application_platformMatch4.2
OR
redhatjboss_enterprise_application_platformMatch4.2cp01
OR
redhatjboss_enterprise_application_platformMatch4.2cp02
OR
redhatjboss_enterprise_application_platformMatch4.2.0cp01
OR
redhatjboss_enterprise_application_platformMatch4.2.0cp02
OR
redhatjboss_enterprise_application_platformMatch4.2.0cp03
OR
redhatjboss_enterprise_application_platformMatch4.2.0cp04
OR
redhatjboss_enterprise_application_platformMatch4.2.0cp05
OR
redhatjboss_enterprise_application_platformMatch4.2.0cp06
OR
redhatjboss_enterprise_application_platformMatch4.2.0cp07
OR
redhatjboss_enterprise_application_platformMatch4.2.2ga

2.1 Low

CVSS2

Attack Vector

LOCAL

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

PARTIAL

Integrity Impact

NONE

Availability Impact

NONE

AV:L/AC:L/Au:N/C:P/I:N/A:N

5.5 Medium

AI Score

Confidence

Low

0.0004 Low

EPSS

Percentile

5.1%