A vulnerability was found in jberet-core logging. An exception in 'dbProperties' might display user credentials such as the username and password for the database-connection.
CVSS Vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:NJberet
APPJberet< 2.2.1Red Hat Jboss Enterprise Application Platform
APPRedhat8.0
🔵
CHECK WITH VENDOR
No clear patch data available. Check vendor references.
References
Related vulnerabilities
CVE-2017-12149CRITICAL9.8⚠ KEVPL ✓same product
RCE przez niebezpieczną deserializację w JBoss HTTP Invoker (EAP 5.2)
CVE-2025-12543CRITICAL9.6PL ✓same product
Brak walidacji nagłówka Host w serwerze Undertow HTTP
CVE-2019-14887CRITICAL9.1PL ✓same product
Wildfly: ignorowanie 'enabled-protocols' umożliwia TLS downgrade
CVE-2019-14892CRITICAL9.8PL ✓same product
RCE poprzez deserializację JNDI w jackson-databind (commons-configuration)
CVE-2019-20444CRITICAL9.1PL ✓same product
Netty: nieprawidłowe parsowanie nagłówków HTTP bez dwukropka (HTTP Request Smuggling)