PT-2009-5842 · Red Hat · Red Hat Jboss Enterprise Application Platform

Marc Schoenefeld

·

Published

2009-12-15

·

Updated

2017-08-17

·

CVE-2009-3554

CVSS v2.0

2.1

Low

VectorAV:L/AC:L/Au:N/C:P/I:N/A:N
Name of the Vulnerable Software and Affected Versions Red Hat JBoss Enterprise Application Platform versions 4.2 before 4.2.0.CP08 Red Hat JBoss Enterprise Application Platform versions 4.3 before 4.3.0.CP07
Description The issue allows local users to obtain sensitive information, such as the JMX password and other command-line arguments, by reading the twiddle.log file. This is because Twiddle in the affected versions of Red Hat JBoss Enterprise Application Platform writes this sensitive information to the log file.
Recommendations For Red Hat JBoss Enterprise Application Platform version 4.2 before 4.2.0.CP08, update to version 4.2.0.CP08 or later. For Red Hat JBoss Enterprise Application Platform version 4.3 before 4.3.0.CP07, update to version 4.3.0.CP07 or later.

Fix

Information Disclosure

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2009-3554
RHSA-2009:1636
RHSA-2009:1637
RHSA-2009:1649
RHSA-2009:1650

Affected Products

Red Hat Jboss Enterprise Application Platform