Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2016-7043

Опубликовано: 14 мая 2019
Источник: redhat
CVSS3: 5.9
CVSS2: 4.3

Описание

It has been reported that KIE server and Busitess Central before version 7.21.0.Final contain username and password as plaintext Java properties. Any app deployed on the same server would have access to these properties, thus granting access to ther services.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat BPM Suite 6kie-serverWill not fix
Red Hat Decision Manager 7kie-serverAffected
Red Hat JBoss BRMS 6kie-serverWill not fix
Red Hat Process Automation 7kie-serverAffected

Показывать по

Дополнительная информация

Статус:

Moderate
Дефект:
CWE-522
https://bugzilla.redhat.com/show_bug.cgi?id=1375760kie-server: Plaintext password storage in kie-server and busitess-central

5.9 Medium

CVSS3

4.3 Medium

CVSS2

Связанные уязвимости

CVSS3: 5.9
nvd
больше 6 лет назад

It has been reported that KIE server and Busitess Central before version 7.21.0.Final contain username and password as plaintext Java properties. Any app deployed on the same server would have access to these properties, thus granting access to ther services.

CVSS3: 9.8
github
больше 3 лет назад

Password in config file in KIE server

5.9 Medium

CVSS3

4.3 Medium

CVSS2