CWE-555: J2EE Misconfiguration: Plaintext Password in Configuration File

low-risk

The J2EE application stores a plaintext password in a configuration file.

Abstraction: Variant

Common Consequences

Access Control Bypass Protection Mechanism

Real-World Examples (2)

CVE CVSS EPSS KEV
CVE-2023-20059 4.3 0.2%
CVE-2025-46119 6.3 0.1%
0
/ 100
low-risk
Active Threat 0/50 · Minimal
Exploit Availability 0/50 · Minimal