CVE-2009-3554
Twiddle in Red Hat JBoss Enterprise Application Platform (aka JBoss EAP or JBEAP) 4.2 before 4.2.0.CP08 and 4.3 before 4.3.0.CP07 writes the JMX password, and other command-line arguments, to the twiddle.log file, which allows local users to obtain…
Does this matter?
Lower severity and a low EPSS score (0.38%). Track it; it rarely justifies an emergency change on its own.
Description
Twiddle in Red Hat JBoss Enterprise Application Platform (aka JBoss EAP or JBEAP) 4.2 before 4.2.0.CP08 and 4.3 before 4.3.0.CP07 writes the JMX password, and other command-line arguments, to the twiddle.log file, which allows local users to obtain sensitive information by reading this file.
- CVSS 2.0
- 2.1 LOWAV:L/AC:L/Au:N/C:P/I:N/A:N
- EPSS
- 0.38% probability · 32th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-200
- Affected
- redhat/jboss enterprise application platform
- Source
- secalert@redhat.com
References
- http://secunia.com/advisories/37671Vendor Advisory
- http://securitytracker.com/id?1023316
- http://www.redhat.com/docs/en-US/JBoss_Enterprise_Application_Platform/4.2.0.cp08/html-single/Release_Notes/index.htmlPatch, Vendor Advisory
- http://www.securityfocus.com/bid/37276
- https://bugzilla.redhat.com/show_bug.cgi?id=532111
- https://bugzilla.redhat.com/show_bug.cgi?id=539495Patch
- https://exchange.xforce.ibmcloud.com/vulnerabilities/54702
- https://jira.jboss.org/jira/browse/JBPAPP-2872
- https://rhn.redhat.com/errata/RHSA-2009-1636.htmlVendor Advisory
- https://rhn.redhat.com/errata/RHSA-2009-1637.htmlVendor Advisory
- https://rhn.redhat.com/errata/RHSA-2009-1649.htmlVendor Advisory
- https://rhn.redhat.com/errata/RHSA-2009-1650.htmlVendor Advisory
- http://secunia.com/advisories/37671Vendor Advisory
- http://securitytracker.com/id?1023316
- http://www.redhat.com/docs/en-US/JBoss_Enterprise_Application_Platform/4.2.0.cp08/html-single/Release_Notes/index.htmlPatch, Vendor Advisory
- http://www.securityfocus.com/bid/37276
- https://bugzilla.redhat.com/show_bug.cgi?id=532111
- https://bugzilla.redhat.com/show_bug.cgi?id=539495Patch
- https://exchange.xforce.ibmcloud.com/vulnerabilities/54702
- https://jira.jboss.org/jira/browse/JBPAPP-2872
- https://rhn.redhat.com/errata/RHSA-2009-1636.htmlVendor Advisory
- https://rhn.redhat.com/errata/RHSA-2009-1637.htmlVendor Advisory
- https://rhn.redhat.com/errata/RHSA-2009-1649.htmlVendor Advisory
- https://rhn.redhat.com/errata/RHSA-2009-1650.htmlVendor Advisory
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.