Total vulnerabilities in the database
twiddle.sh in JBoss AS 5.0 and EAP 5.0 and earlier accepts credentials as command-line arguments, which allows local users to read the credentials by listing the process and its arguments.
Software | From | Fixed in |
---|---|---|
redhat / jboss_community_application_server | 5.0.0 | 5.0.0.x |
redhat / jboss_enterprise_application_platform | 5.0.0 | 5.0.0.x |