The monitor perl script in the Sybase database plug-in in SpringSource Hyperic HQ before 4.3 allows local users to obtain the database password by listing the process and its arguments.
The product exposes sensitive information to an actor that is not explicitly authorized to have access to that information.