CVE-2016-7043
Summary
| CVE | CVE-2016-7043 |
|---|---|
| State | PUBLIC |
| Assigner | [email protected] |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2019-05-15 16:29:00 UTC |
| Updated | 2023-02-12 23:25:00 UTC |
| Description | It has been reported that KIE server and Busitess Central before version 7.21.0.Final contain username and password as plaintext Java properties. Any app deployed on the same server would have access to these properties, thus granting access to ther services. |
Risk And Classification
Problem Types: CWE-260
NVD Known Affected Configurations (CPE 2.3)
| Type | Vendor | Product | Version | Update | Edition | Language |
|---|---|---|---|---|---|---|
| Application | Redhat | Kie-server | All | All | All | All |
| Application | Redhat | Kie-server | All | All | All | All |
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| 1375760 – (CVE-2016-7043) CVE-2016-7043 kie-server: Plaintext password storage in kie-server and busitess-central | CONFIRM | bugzilla.redhat.com | Issue Tracking, Third Party Advisory |
| [RHBMS-4312] Loading pasword from a keystore by rstancel · Pull Request #1273 · kiegroup/droolsjbpm-integration · GitHub | CONFIRM | github.com | Patch, Third Party Advisory |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
No vendor comments have been submitted for this CVE.
There are currently no legacy QID mappings associated with this CVE.