CVE-2009-3554
15.12.2009, 18:30
Twiddle in Red Hat JBoss Enterprise Application Platform (aka JBoss EAP or JBEAP) 4.2 before 4.2.0.CP08 and 4.3 before 4.3.0.CP07 writes the JMX password, and other command-line arguments, to the twiddle.log file, which allows local users to obtain sensitive information by reading this file.Enginsight
| Vendor | Product | Version |
|---|---|---|
| redhat | jboss_enterprise_application_platform | 4.2 |
| redhat | jboss_enterprise_application_platform | 4.2:cp01 |
| redhat | jboss_enterprise_application_platform | 4.2:cp02 |
| redhat | jboss_enterprise_application_platform | 4.2.0:cp01 |
| redhat | jboss_enterprise_application_platform | 4.2.0:cp02 |
| redhat | jboss_enterprise_application_platform | 4.2.0:cp03 |
| redhat | jboss_enterprise_application_platform | 4.2.0:cp04 |
| redhat | jboss_enterprise_application_platform | 4.2.0:cp05 |
| redhat | jboss_enterprise_application_platform | 4.2.0:cp06 |
| redhat | jboss_enterprise_application_platform | 4.2.0:cp07 |
| redhat | jboss_enterprise_application_platform | 4.2.2:ga |
𝑥
= Vulnerable software versions
Ubuntu Releases
Common Weakness Enumeration
References