Vulnerability Name:

CVE-2009-5066 (CCN-77784)

Assigned:2009-10-01
Published:2009-10-01
Updated:2015-01-18
Summary:twiddle.sh in JBoss AS 5.0 and EAP 5.0 and earlier accepts credentials as command-line arguments, which allows local users to read the credentials by listing the process and its arguments.
CVSS v3 Severity:4.0 Medium (CCN CVSS v3.1 Vector: CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N)
Exploitability Metrics:Attack Vector (AV): Local
Attack Complexity (AC): Low
Privileges Required (PR): None
User Interaction (UI): None
Scope:Scope (S): Unchanged
Impact Metrics:Confidentiality (C): Low
Integrity (I): None
Availibility (A): None
CVSS v2 Severity:2.1 Low (CVSS v2 Vector: AV:L/AC:L/Au:N/C:P/I:N/A:N)
1.6 Low (Temporal CVSS v2 Vector: AV:L/AC:L/Au:N/C:P/I:N/A:N/E:U/RL:OF/RC:C)
Exploitability Metrics:Access Vector (AV): Local
Access Complexity (AC): Low
Authentication (Au): None
Impact Metrics:Confidentiality (C): Partial
Integrity (I): None
Availibility (A): None
2.1 Low (CCN CVSS v2 Vector: AV:L/AC:L/Au:N/C:P/I:N/A:N)
1.6 Low (CCN Temporal CVSS v2 Vector: AV:L/AC:L/Au:N/C:P/I:N/A:N/E:U/RL:OF/RC:C)
Exploitability Metrics:Access Vector (AV): Local
Access Complexity (AC): Low
Athentication (Au): None
Impact Metrics:Confidentiality (C): Partial
Integrity (I): None
Availibility (A): None
Vulnerability Type:CWE-255
Vulnerability Consequences:Obtain Information
References:Source: MITRE
Type: CNA
CVE-2009-5066

Source: MISC
Type: UNKNOWN
http://objectopia.com/2009/10/01/securing-jmx-invoker-layer-in-jboss/

Source: CCN
Type: RHSA-2013-0191
Important: JBoss Enterprise Application Platform 5.2.0 update

Source: REDHAT
Type: UNKNOWN
RHSA-2013:0191

Source: CCN
Type: RHSA-2013-0192
Important: JBoss Enterprise Application Platform 5.2.0 update

Source: REDHAT
Type: UNKNOWN
RHSA-2013:0192

Source: CCN
Type: RHSA-2013-0193
Important: JBoss Enterprise Application Platform 5.2.0 update

Source: REDHAT
Type: UNKNOWN
RHSA-2013:0193

Source: CCN
Type: RHSA-2013-0194
Important: JBoss Enterprise Application Platform 5.2.0 update

Source: REDHAT
Type: UNKNOWN
RHSA-2013:0194

Source: CCN
Type: RHSA-2013-0195
Important: JBoss Enterprise Web Platform 5.2.0 update

Source: REDHAT
Type: UNKNOWN
RHSA-2013:0195

Source: CCN
Type: RHSA-2013-0196
Important: JBoss Enterprise Web Platform 5.2.0 update

Source: REDHAT
Type: UNKNOWN
RHSA-2013:0196

Source: CCN
Type: RHSA-2013-0197
Important: JBoss Enterprise Web Platform 5.2.0 update

Source: REDHAT
Type: UNKNOWN
RHSA-2013:0197

Source: CCN
Type: RHSA-2013-0198
Important: JBoss Enterprise Web Platform 5.2.0 update

Source: REDHAT
Type: UNKNOWN
RHSA-2013:0198

Source: REDHAT
Type: UNKNOWN
RHSA-2013:0221

Source: REDHAT
Type: UNKNOWN
RHSA-2013:0533

Source: SECUNIA
Type: UNKNOWN
51984

Source: SECUNIA
Type: UNKNOWN
52054

Source: CCN
Type: JBoss Web site
JBoss Enterprise Application Platform

Source: MLIST
Type: UNKNOWN
[oss-security] 20120720 CVE for JBOSS EAP 5.0(twiddle and jmx invocations) ?

Source: MLIST
Type: UNKNOWN
[oss-security] 20120723 Re: CVE for JBOSS EAP 5.0(twiddle and jmx invocations) ?

Source: CCN
Type: OSVDB ID: 84730
JBoss twiddle.sh Credential Command-line Argument Local Credential Disclosure

Source: CCN
Type: BID-54631
JBoss 'twiddle.sh' Local Information Disclosure Vulnerability

Source: XF
Type: UNKNOWN
jboss-twiddle-info-disc(77784)

Source: CCN
Type: JBPAPP-3391
Provide twiddle credentials external to the command line

Source: CONFIRM
Type: UNKNOWN
https://issues.jboss.org/browse/JBPAPP-3391?_sscc=t

Vulnerable Configuration:Configuration 1:
  • cpe:/a:redhat:jboss_community_application_server:5.0.0:*:*:*:*:*:*:*
  • OR cpe:/a:redhat:jboss_enterprise_application_platform:5.0.0:*:*:*:*:*:*:*

  • Configuration CCN 1:
  • cpe:/a:redhat:jboss_enterprise_application_platform:5.0.0:*:*:*:*:*:*:*
  • OR cpe:/a:redhat:jboss_community_application_server:5.0.0:*:*:*:*:*:*:*

  • * Denotes that component is vulnerable
    Oval Definitions
    Definition IDClassTitleLast Modified
    oval:com.ubuntu.precise:def:20095066000
    V
    CVE-2009-5066 on Ubuntu 12.04 LTS (precise) - low.
    2012-08-13
    BACK
    redhat jboss community application server 5.0.0
    redhat jboss enterprise application platform 5.0.0
    redhat jboss enterprise application platform 5.0.0
    redhat jboss community application server 5.0.0