Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2016-7043

Опубликовано: 15 мая 2019
Источник: nvd
CVSS3: 5.9
CVSS3: 9.8
CVSS2: 5
EPSS Низкий

Описание

It has been reported that KIE server and Busitess Central before version 7.21.0.Final contain username and password as plaintext Java properties. Any app deployed on the same server would have access to these properties, thus granting access to ther services.

Уязвимые конфигурации

Конфигурация 1
cpe:2.3:a:redhat:kie-server:*:*:*:*:*:*:*:*
Версия до 7.21.0 (исключая)

EPSS

Процентиль: 53%
0.00298
Низкий

5.9 Medium

CVSS3

9.8 Critical

CVSS3

5 Medium

CVSS2

Дефекты

CWE-260
CWE-255

Связанные уязвимости

CVSS3: 5.9
redhat
больше 6 лет назад

It has been reported that KIE server and Busitess Central before version 7.21.0.Final contain username and password as plaintext Java properties. Any app deployed on the same server would have access to these properties, thus granting access to ther services.

CVSS3: 9.8
github
больше 3 лет назад

Password in config file in KIE server

EPSS

Процентиль: 53%
0.00298
Низкий

5.9 Medium

CVSS3

9.8 Critical

CVSS3

5 Medium

CVSS2

Дефекты

CWE-260
CWE-255