MEDIUM
The Embedded Jopr component in JBoss Application Server includes the cleartext datasource password in unspecified HTML responses, which might allow (1) man-in-the-middle attackers to obtain sensitive information by leveraging failure to use SSL or (2) attackers to obtain sensitive information by reading the HTML source code
Published Oct 24, 2017
6.6
MEDIUMCVSS 3.0
EPSS 1.58%
Description
Affected products
Remediation
Metrics
References (3)
Change history (0)
No recorded changes yet.