CVE-2016-7043
MEDIUMKIE Server < 7.21.0 - Plaintext Password Exposure in Java Properties
Title source: llmDescription
It has been reported that KIE server and Busitess Central before version 7.21.0.Final contain username and password as plaintext Java properties. Any app deployed on the same server would have access to these properties, thus granting access to ther services.
References (2)
Core 2
Core References
Issue Tracking, Third Party Advisory x_refsource_confirm
https://bugzilla.redhat.com/show_bug.cgi?id=CVE-2016-7043
Patch, Third Party Advisory x_refsource_confirm
https://github.com/kiegroup/droolsjbpm-integration/pull/1273
Scores
CVSS v3
5.9
EPSS
0.0153
EPSS Percentile
72.0%
Attack Vector
NETWORK
CVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N
Details
CWE
CWE-255
CWE-260
Status
published
Products (2)
org.kie.server/kie-server-common
0 - 7.21.0.FinalMaven
redhat/kie-server
< 7.21.0
Published
May 15, 2019
Tracked Since
Feb 18, 2026