PT-2009-5842 · Red Hat · Red Hat Jboss Enterprise Application Platform

Marc Schoenefeld

·

Publicado

2009-12-15

·

Atualizado

2017-08-17

·

CVE-2009-3554

CVSS v2.0

2.1

Baixa

VetorAV:L/AC:L/Au:N/C:P/I:N/A:N
Name of the Vulnerable Software and Affected Versions Red Hat JBoss Enterprise Application Platform versions 4.2 before 4.2.0.CP08 Red Hat JBoss Enterprise Application Platform versions 4.3 before 4.3.0.CP07
Description The issue allows local users to obtain sensitive information, such as the JMX password and other command-line arguments, by reading the twiddle.log file. This is because Twiddle in the affected versions of Red Hat JBoss Enterprise Application Platform writes this sensitive information to the log file.
Recommendations For Red Hat JBoss Enterprise Application Platform version 4.2 before 4.2.0.CP08, update to version 4.2.0.CP08 or later. For Red Hat JBoss Enterprise Application Platform version 4.3 before 4.3.0.CP07, update to version 4.3.0.CP07 or later.

Correção

Information Disclosure

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

CVE-2009-3554
RHSA-2009:1636
RHSA-2009:1637
RHSA-2009:1649
RHSA-2009:1650

Produtos afetados

Red Hat Jboss Enterprise Application Platform