CVE-2009-5066
published 2012-08-13CVE-2009-5066: twiddle.sh in JBoss AS 5.0 and EAP 5.0 and earlier accepts credentials as command-line arguments, which allows local users to read the credentials by listing…
PriorityP47low2.1CVSS 2.0
AVLACLAuNCPINAN
EPSS
0.39%
30.9th percentile
twiddle.sh in JBoss AS 5.0 and EAP 5.0 and earlier accepts credentials as command-line arguments, which allows local users to read the credentials by listing the process and its arguments.
Affected
2 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| redhat | jboss_community_application_server | — | — |
| redhat | jboss_enterprise_application_platform | — | — |
CVSS provenance
nvdv2.02.1LOWAV:L/AC:L/Au:N/C:P/I:N/A:N
vendor_redhat2.1LOW
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-2g9h-3ggp-8xg3: twiddle
ghsa_unreviewed·2022-05-02
CVE-2009-5066 [LOW] GHSA-2g9h-3ggp-8xg3: twiddle
twiddle.sh in JBoss AS 5.0 and EAP 5.0 and earlier accepts credentials as command-line arguments, which allows local users to read the credentials by listing the process and its arguments.
Red Hat
JBoss: twiddle.sh accepts credentials as command line arguments, exposing them to other local users via a process listing
vendor_redhat·2009-10-01·CVSS 2.1
CVE-2009-5066 [LOW] JBoss: twiddle.sh accepts credentials as command line arguments, exposing them to other local users via a process listing
JBoss: twiddle.sh accepts credentials as command line arguments, exposing them to other local users via a process listing
twiddle.sh in JBoss AS 5.0 and EAP 5.0 and earlier accepts credentials as command-line arguments, which allows local users to read the credentials by listing the process and its arguments.
Package: twiddle (Red Hat JBoss BRMS 5) - Affected
Package: twiddle (Red Hat JBoss Portal 5) - Will not fix
Package: twiddle (Red Hat JBoss SOA Platform 5) - Affected
No detection rules found.
No public exploits indexed.
http://objectopia.com/2009/10/01/securing-jmx-invoker-layer-in-jboss/http://rhn.redhat.com/errata/RHSA-2013-0191.htmlhttp://rhn.redhat.com/errata/RHSA-2013-0192.htmlhttp://rhn.redhat.com/errata/RHSA-2013-0193.htmlhttp://rhn.redhat.com/errata/RHSA-2013-0194.htmlhttp://rhn.redhat.com/errata/RHSA-2013-0195.htmlhttp://rhn.redhat.com/errata/RHSA-2013-0196.htmlhttp://rhn.redhat.com/errata/RHSA-2013-0197.htmlhttp://rhn.redhat.com/errata/RHSA-2013-0198.htmlhttp://rhn.redhat.com/errata/RHSA-2013-0221.htmlhttp://rhn.redhat.com/errata/RHSA-2013-0533.htmlhttp://secunia.com/advisories/51984http://secunia.com/advisories/52054http://www.openwall.com/lists/oss-security/2012/07/20/1http://www.openwall.com/lists/oss-security/2012/07/23/2https://issues.jboss.org/browse/JBPAPP-3391?_sscc=thttp://objectopia.com/2009/10/01/securing-jmx-invoker-layer-in-jboss/http://rhn.redhat.com/errata/RHSA-2013-0191.htmlhttp://rhn.redhat.com/errata/RHSA-2013-0192.htmlhttp://rhn.redhat.com/errata/RHSA-2013-0193.htmlhttp://rhn.redhat.com/errata/RHSA-2013-0194.htmlhttp://rhn.redhat.com/errata/RHSA-2013-0195.htmlhttp://rhn.redhat.com/errata/RHSA-2013-0196.htmlhttp://rhn.redhat.com/errata/RHSA-2013-0197.htmlhttp://rhn.redhat.com/errata/RHSA-2013-0198.htmlhttp://rhn.redhat.com/errata/RHSA-2013-0221.htmlhttp://rhn.redhat.com/errata/RHSA-2013-0533.htmlhttp://secunia.com/advisories/51984http://secunia.com/advisories/52054http://www.openwall.com/lists/oss-security/2012/07/20/1http://www.openwall.com/lists/oss-security/2012/07/23/2https://issues.jboss.org/browse/JBPAPP-3391?_sscc=t
2012-08-13
Published