CVE-2009-3554
Last modified
CVE-2009-3554 is a vulnerability of currently unknown severity. Twiddle in Red Hat JBoss Enterprise Application Platform (aka JBoss EAP or JBEAP) 4.2 before 4.2.0.CP08 and 4.3 before 4.3.0.CP07 writes the JMX password, and other command-line arguments, to the twiddle.log file, which allows local users to obtain sensitive information by reading this file.. EPSS estimates a 0.38% chance of exploitation in the next 30 days.
Description
Twiddle in Red Hat JBoss Enterprise Application Platform (aka JBoss EAP or JBEAP) 4.2 before 4.2.0.CP08 and 4.3 before 4.3.0.CP07 writes the JMX password, and other command-line arguments, to the twiddle.log file, which allows local users to obtain sensitive information by reading this file.
Metrics
Weakness Enumeration
Affected Software
| Vendor | Product | Versions | Update |
|---|---|---|---|
| Redhat | Jboss Enterprise Application Platform | 4.2 | — |
| Redhat | Jboss Enterprise Application Platform | 4.2.0 | Cp01 |
| Redhat | Jboss Enterprise Application Platform | 4.2.2 | Ga |
References
- http://secunia.com/advisories/37671Vendor Advisory
- https://rhn.redhat.com/errata/RHSA-2009-1636.htmlVendor Advisory
- https://rhn.redhat.com/errata/RHSA-2009-1637.htmlVendor Advisory
- https://rhn.redhat.com/errata/RHSA-2009-1649.htmlVendor Advisory
- https://rhn.redhat.com/errata/RHSA-2009-1650.htmlVendor Advisory
- http://secunia.com/advisories/37671Vendor Advisory
- https://rhn.redhat.com/errata/RHSA-2009-1636.htmlVendor Advisory
- https://rhn.redhat.com/errata/RHSA-2009-1637.htmlVendor Advisory
- https://rhn.redhat.com/errata/RHSA-2009-1649.htmlVendor Advisory
- https://rhn.redhat.com/errata/RHSA-2009-1650.htmlVendor Advisory
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2009-3554?
How severe is CVE-2009-3554?
How do I fix CVE-2009-3554?
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2009
- CVE-2009-3548The Windows installer for Apache Tomcat 6.0.0 through 6.0.20…
- CVE-2009-3549packet-paltalk.c in the Paltalk dissector in Wireshark 1.2.0…
- CVE-2009-3550The DCERPC/NT dissector in Wireshark 0.10.10 through 1.0.9 a…
- CVE-2009-3551Off-by-one error in the dissect_negprot_response function in…
- CVE-2009-3552In RHEV-M VDC 2.2.0, it was found that the SSL certificate w…3.1
- CVE-2009-3553Use-after-free vulnerability in the abstract file-descriptor…7.5
- CVE-2009-3555The TLS protocol, and the SSL protocol 3.0 and possibly earl…9.8
- CVE-2009-3556A certain Red Hat configuration step for the qla2xxx driver …
- CVE-2009-3557The tempnam function in ext/standard/file.c in PHP before 5.…
- CVE-2009-3558The posix_mkfifo function in ext/posix/posix.c in PHP before…
- CVE-2009-3559main/streams/plain_wrapper.c in PHP 5.3.x before 5.3.1 does …
- CVE-2009-3560The big2_toUtf8 function in lib/xmltok.c in libexpat in Expa…
Are you affected by CVE-2009-3554?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
