We found results for “”
CVE-2016-7043
Good to know:
Date: May 15, 2019
It has been reported that KIE server and Busitess Central before version 7.21.0.Final contain username and password as plaintext Java properties. Any app deployed on the same server would have access to these properties, thus granting access to ther services.
Language: Java
Severity Score
Severity Score
Top Fix
Upgrade Version
Upgrade to version org.kie.server:kie-server-common:7.21.0.Final,org.kie.server:kie-server-controller-rest:7.21.0.Final,org.kie.server:kie-server-controller-websocket-client:7.21.0.Final,org.kie.server:kie-server-services-common:7.21.0.Final
CVSS v3.1
Base Score: |
|
---|---|
Attack Vector (AV): | NETWORK |
Attack Complexity (AC): | LOW |
Privileges Required (PR): | NONE |
User Interaction (UI): | NONE |
Scope (S): | UNCHANGED |
Confidentiality (C): | HIGH |
Integrity (I): | HIGH |
Availability (A): | HIGH |
CVSS v2
Base Score: |
|
---|---|
Access Vector (AV): | NETWORK |
Access Complexity (AC): | LOW |
Authentication (AU): | NONE |
Confidentiality (C): | PARTIAL |
Integrity (I): | NONE |
Availability (A): | NONE |
Additional information: |