{"api_version":"1","generated_at":"2026-07-23T19:43:54+00:00","cve":"CVE-2016-7043","urls":{"html":"https://cve.report/CVE-2016-7043","api":"https://cve.report/api/cve/CVE-2016-7043.json","docs":"https://cve.report/api","cve_org":"https://www.cve.org/CVERecord?id=CVE-2016-7043","nvd":"https://nvd.nist.gov/vuln/detail/CVE-2016-7043"},"summary":{"title":"CVE-2016-7043","description":"It has been reported that KIE server and Busitess Central before version 7.21.0.Final contain username and password as plaintext Java properties. Any app deployed on the same server would have access to these properties, thus granting access to ther services.","state":"PUBLIC","assigner":"secalert@redhat.com","published_at":"2019-05-15 16:29:00","updated_at":"2023-02-12 23:25:00"},"problem_types":["CWE-260"],"metrics":[],"references":[{"url":"https://bugzilla.redhat.com/show_bug.cgi?id=CVE-2016-7043","name":"https://bugzilla.redhat.com/show_bug.cgi?id=CVE-2016-7043","refsource":"CONFIRM","tags":["Issue Tracking","Third Party Advisory"],"title":"1375760 – (CVE-2016-7043) CVE-2016-7043 kie-server: Plaintext password storage in kie-server and busitess-central","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"https://github.com/kiegroup/droolsjbpm-integration/pull/1273","name":"https://github.com/kiegroup/droolsjbpm-integration/pull/1273","refsource":"CONFIRM","tags":["Patch","Third Party Advisory"],"title":"[RHBMS-4312] Loading pasword from a keystore by rstancel · Pull Request #1273 · kiegroup/droolsjbpm-integration · GitHub","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"https://www.cve.org/CVERecord?id=CVE-2016-7043","name":"CVE Program record","refsource":"CVE.ORG","tags":["canonical"]},{"url":"https://nvd.nist.gov/vuln/detail/CVE-2016-7043","name":"NVD vulnerability detail","refsource":"NVD","tags":["canonical","analysis"]}],"affected":[],"timeline":[],"solutions":[],"workarounds":[],"exploits":[],"credits":[],"nvd_cpes":[{"cve_year":"2016","cve_id":"7043","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"redhat","cpe5":"kie-server","cpe6":"*","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"},{"cve_year":"2016","cve_id":"7043","vulnerable":"1","versionEndIncluding":"1","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"redhat","cpe5":"kie-server","cpe6":"*","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"}],"vendor_comments":[],"enrichments":{"kev":null,"epss":null,"legacy_qids":[]},"source_records":{"cve_program":{"data_version":"4.0","data_type":"CVE","data_format":"MITRE","CVE_data_meta":{"ID":"CVE-2016-7043","ASSIGNER":"secalert@redhat.com","STATE":"PUBLIC"},"description":{"description_data":[{"lang":"eng","value":"It has been reported that KIE server and Busitess Central before version 7.21.0.Final contain username and password as plaintext Java properties. Any app deployed on the same server would have access to these properties, thus granting access to ther services."}]},"problemtype":{"problemtype_data":[{"description":[{"lang":"eng","value":"CWE-260","cweId":"CWE-260"}]}]},"affects":{"vendor":{"vendor_data":[{"vendor_name":"KIE","product":{"product_data":[{"product_name":"kie-server","version":{"version_data":[{"version_affected":"=","version_value":"affects < 7.21.0.Final"}]}}]}}]}},"references":{"reference_data":[{"url":"https://bugzilla.redhat.com/show_bug.cgi?id=CVE-2016-7043","refsource":"MISC","name":"https://bugzilla.redhat.com/show_bug.cgi?id=CVE-2016-7043"},{"url":"https://github.com/kiegroup/droolsjbpm-integration/pull/1273","refsource":"MISC","name":"https://github.com/kiegroup/droolsjbpm-integration/pull/1273"}]},"impact":{"cvss":[{"attackComplexity":"HIGH","attackVector":"NETWORK","availabilityImpact":"NONE","baseScore":5.9,"baseSeverity":"MEDIUM","confidentialityImpact":"HIGH","integrityImpact":"NONE","privilegesRequired":"NONE","scope":"UNCHANGED","userInteraction":"NONE","vectorString":"CVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N","version":"3.0"}]}},"nvd":{"publishedDate":"2019-05-15 16:29:00","lastModifiedDate":"2023-02-12 23:25:00","problem_types":["CWE-260"],"metrics":{"baseMetricV3":{"cvssV3":{"version":"3.0","vectorString":"CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"HIGH","integrityImpact":"HIGH","availabilityImpact":"HIGH","baseScore":9.8,"baseSeverity":"CRITICAL"},"exploitabilityScore":3.9,"impactScore":5.9},"baseMetricV2":{"cvssV2":{"version":"2.0","vectorString":"AV:N/AC:L/Au:N/C:P/I:N/A:N","accessVector":"NETWORK","accessComplexity":"LOW","authentication":"NONE","confidentialityImpact":"PARTIAL","integrityImpact":"NONE","availabilityImpact":"NONE","baseScore":5},"severity":"MEDIUM","exploitabilityScore":10,"impactScore":2.9,"acInsufInfo":false,"obtainAllPrivilege":false,"obtainUserPrivilege":false,"obtainOtherPrivilege":false,"userInteractionRequired":false}},"configurations":{"CVE_data_version":"4.0","nodes":[{"operator":"OR","children":[],"cpe_match":[{"vulnerable":true,"cpe23Uri":"cpe:2.3:a:redhat:kie-server:*:*:*:*:*:*:*:*","versionEndExcluding":"7.21.0","cpe_name":[]}]}]}},"legacy_mitre":{"record":{"CveYear":"2016","CveId":"7043","Ordinal":"93349","Title":"CVE-2016-7043","CVE":"CVE-2016-7043","Year":"2016"},"notes":[{"CveYear":"2016","CveId":"7043","Ordinal":"1","NoteData":"It has been reported that KIE server and Busitess Central before version 7.21.0.Final contain username and password as plaintext Java properties. Any app deployed on the same server would have access to these properties, thus granting access to ther services.","Type":"Description","Title":null},{"CveYear":"2016","CveId":"7043","Ordinal":"2","NoteData":"2019-05-15","Type":"Other","Title":"Published"},{"CveYear":"2016","CveId":"7043","Ordinal":"3","NoteData":"2019-05-15","Type":"Other","Title":"Modified"}]}}}