CVE-2009-2899: Infoleak
Published Dec 5, 2012
·Updated
The monitor perl script in the Sybase database plug-in in SpringSource Hyperic HQ before 4.3 allows local users to obtain the database password by listing the process and its arguments.
Affected Software
1 affected component
VMware Hyperic HQ<=4.2
Event History
Dec 5, 2012
CVE Published
via MITRE·05:00 PM
Data Sourced
via MITRE·05:00 PM
Description
Frequently Asked Questions
1
What is the severity of CVE-2009-2899?
CVE-2009-2899 is categorized as a medium severity vulnerability due to potential exposure of sensitive database credentials.
2
How do I fix CVE-2009-2899?
To fix CVE-2009-2899, upgrade to VMware Hyperic HQ version 4.3 or later.
3
Who is affected by CVE-2009-2899?
CVE-2009-2899 affects local users of VMware Hyperic HQ versions prior to 4.3.
4
What specifically is compromised in CVE-2009-2899?
CVE-2009-2899 allows local users to obtain database passwords by listing process arguments.
5
Is CVE-2009-2899 still relevant today?
While CVE-2009-2899 was identified over a decade ago, its relevance diminishes with the discontinuation of affected software, but legacy systems may still be at risk.