CVE-2009-5066: Low severity red hat jboss community application server vulnerability
twiddle.sh in JBoss AS 5.0 and EAP 5.0 and earlier accepts credentials as command-line arguments, which allows local users to read the credentials by listing the process and its arguments.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2009-5066?
CVE-2009-5066 is considered a medium severity vulnerability due to the potential exposure of sensitive credentials.
How do I fix CVE-2009-5066?
To fix CVE-2009-5066, avoid passing sensitive credentials as command-line arguments and use environmental variables or configuration files instead.
Who is affected by CVE-2009-5066?
CVE-2009-5066 affects users of JBoss AS 5.0 and EAP 5.0 and earlier versions.
What kind of exposure does CVE-2009-5066 cause?
CVE-2009-5066 can lead to local users being able to view sensitive credentials by listing the process arguments.
Is CVE-2009-5066 still relevant today?
While JBoss AS 5.0 and EAP 5.0 are old versions, vulnerabilities like CVE-2009-5066 serve as important reminders about secure handling of credentials in applications.