CVE-2016-7043

MEDIUM

KIE Server < 7.21.0 - Plaintext Password Exposure in Java Properties

Title source: llm
STIX 2.1

Description

It has been reported that KIE server and Busitess Central before version 7.21.0.Final contain username and password as plaintext Java properties. Any app deployed on the same server would have access to these properties, thus granting access to ther services.

References (2)

Core 2
Core References
Issue Tracking, Third Party Advisory x_refsource_confirm
https://bugzilla.redhat.com/show_bug.cgi?id=CVE-2016-7043
Patch, Third Party Advisory x_refsource_confirm
https://github.com/kiegroup/droolsjbpm-integration/pull/1273

Scores

CVSS v3 5.9
EPSS 0.0153
EPSS Percentile 72.0%
Attack Vector NETWORK
CVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N

Details

CWE
CWE-255 CWE-260
Status published
Products (2)
org.kie.server/kie-server-common 0 - 7.21.0.FinalMaven
redhat/kie-server < 7.21.0
Published May 15, 2019
Tracked Since Feb 18, 2026