CVE-2016-7043

Source
https://nvd.nist.gov/vuln/detail/CVE-2016-7043
Import Source
https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2016-7043.json
JSON Data
https://api.osv.dev/v1/vulns/CVE-2016-7043
Aliases
Published
2019-05-15T16:29:00Z
Modified
2024-05-13T23:40:04Z
Severity
  • 9.8 (Critical) CVSS_V3 - CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H CVSS Calculator
Summary
[none]
Details

It has been reported that KIE server and Busitess Central before version 7.21.0.Final contain username and password as plaintext Java properties. Any app deployed on the same server would have access to these properties, thus granting access to ther services.

References

Affected packages

Git / github.com/kiegroup/droolsjbpm-integration

Affected ranges

Type
GIT
Repo
https://github.com/kiegroup/droolsjbpm-integration
Events
Introduced
0 Unknown introduced commit / All previous commits are affected
Fixed