CVE-2009-5066

twiddle.sh in JBoss AS 5.0 and EAP 5.0 and earlier accepts credentials as command-line arguments, which allows local users to read the credentials by listing the process and its arguments.
References
Link Resource
http://objectopia.com/2009/10/01/securing-jmx-invoker-layer-in-jboss/ URL Repurposed
http://rhn.redhat.com/errata/RHSA-2013-0191.html
http://rhn.redhat.com/errata/RHSA-2013-0192.html
http://rhn.redhat.com/errata/RHSA-2013-0193.html
http://rhn.redhat.com/errata/RHSA-2013-0194.html
http://rhn.redhat.com/errata/RHSA-2013-0195.html
http://rhn.redhat.com/errata/RHSA-2013-0196.html
http://rhn.redhat.com/errata/RHSA-2013-0197.html
http://rhn.redhat.com/errata/RHSA-2013-0198.html
http://rhn.redhat.com/errata/RHSA-2013-0221.html
http://rhn.redhat.com/errata/RHSA-2013-0533.html
http://secunia.com/advisories/51984
http://secunia.com/advisories/52054
http://www.openwall.com/lists/oss-security/2012/07/20/1
http://www.openwall.com/lists/oss-security/2012/07/23/2
https://issues.jboss.org/browse/JBPAPP-3391?_sscc=t
http://objectopia.com/2009/10/01/securing-jmx-invoker-layer-in-jboss/ URL Repurposed
http://rhn.redhat.com/errata/RHSA-2013-0191.html
http://rhn.redhat.com/errata/RHSA-2013-0192.html
http://rhn.redhat.com/errata/RHSA-2013-0193.html
http://rhn.redhat.com/errata/RHSA-2013-0194.html
http://rhn.redhat.com/errata/RHSA-2013-0195.html
http://rhn.redhat.com/errata/RHSA-2013-0196.html
http://rhn.redhat.com/errata/RHSA-2013-0197.html
http://rhn.redhat.com/errata/RHSA-2013-0198.html
http://rhn.redhat.com/errata/RHSA-2013-0221.html
http://rhn.redhat.com/errata/RHSA-2013-0533.html
http://secunia.com/advisories/51984
http://secunia.com/advisories/52054
http://www.openwall.com/lists/oss-security/2012/07/20/1
http://www.openwall.com/lists/oss-security/2012/07/23/2
https://issues.jboss.org/browse/JBPAPP-3391?_sscc=t
Configurations

Configuration 1 (hide)

OR cpe:2.3:a:redhat:jboss_community_application_server:5.0.0:*:*:*:*:*:*:*
cpe:2.3:a:redhat:jboss_enterprise_application_platform:5.0.0:*:*:*:*:*:*:*

History

21 Nov 2024, 01:11

Type Values Removed Values Added
References () http://objectopia.com/2009/10/01/securing-jmx-invoker-layer-in-jboss/ - URL Repurposed () http://objectopia.com/2009/10/01/securing-jmx-invoker-layer-in-jboss/ - URL Repurposed
References () http://rhn.redhat.com/errata/RHSA-2013-0191.html - () http://rhn.redhat.com/errata/RHSA-2013-0191.html -
References () http://rhn.redhat.com/errata/RHSA-2013-0192.html - () http://rhn.redhat.com/errata/RHSA-2013-0192.html -
References () http://rhn.redhat.com/errata/RHSA-2013-0193.html - () http://rhn.redhat.com/errata/RHSA-2013-0193.html -
References () http://rhn.redhat.com/errata/RHSA-2013-0194.html - () http://rhn.redhat.com/errata/RHSA-2013-0194.html -
References () http://rhn.redhat.com/errata/RHSA-2013-0195.html - () http://rhn.redhat.com/errata/RHSA-2013-0195.html -
References () http://rhn.redhat.com/errata/RHSA-2013-0196.html - () http://rhn.redhat.com/errata/RHSA-2013-0196.html -
References () http://rhn.redhat.com/errata/RHSA-2013-0197.html - () http://rhn.redhat.com/errata/RHSA-2013-0197.html -
References () http://rhn.redhat.com/errata/RHSA-2013-0198.html - () http://rhn.redhat.com/errata/RHSA-2013-0198.html -
References () http://rhn.redhat.com/errata/RHSA-2013-0221.html - () http://rhn.redhat.com/errata/RHSA-2013-0221.html -
References () http://rhn.redhat.com/errata/RHSA-2013-0533.html - () http://rhn.redhat.com/errata/RHSA-2013-0533.html -
References () http://secunia.com/advisories/51984 - () http://secunia.com/advisories/51984 -
References () http://secunia.com/advisories/52054 - () http://secunia.com/advisories/52054 -
References () http://www.openwall.com/lists/oss-security/2012/07/20/1 - () http://www.openwall.com/lists/oss-security/2012/07/20/1 -
References () http://www.openwall.com/lists/oss-security/2012/07/23/2 - () http://www.openwall.com/lists/oss-security/2012/07/23/2 -
References () https://issues.jboss.org/browse/JBPAPP-3391?_sscc=t - () https://issues.jboss.org/browse/JBPAPP-3391?_sscc=t -

14 Feb 2024, 01:17

Type Values Removed Values Added
References (MISC) http://objectopia.com/2009/10/01/securing-jmx-invoker-layer-in-jboss/ - (MISC) http://objectopia.com/2009/10/01/securing-jmx-invoker-layer-in-jboss/ - URL Repurposed

Information

Published : 2012-08-13 20:55

Updated : 2024-11-21 01:11


NVD link : CVE-2009-5066

Mitre link : CVE-2009-5066

CVE.ORG link : CVE-2009-5066


JSON object : View

Products Affected

redhat

  • jboss_enterprise_application_platform
  • jboss_community_application_server
CWE
CWE-255

Credentials Management Errors