CVE-2018-14627
Severity CVSS v4.0:
Pending analysis
Type:
CWE-319
Cleartext Transmission of Sensitive Information
Publication date:
04/09/2018
Last modified:
03/10/2019
Description
The IIOP OpenJDK Subsystem in WildFly before version 14.0.0 does not honour configuration when SSL transport is required. Servers before this version that are configured with the following setting allow clients to create plaintext connections:
Impact
Base Score 3.x
5.90
Severity 3.x
MEDIUM
Base Score 2.0
4.30
Severity 2.0
MEDIUM
Vulnerable products and versions
| CPE | From | Up to |
|---|---|---|
| cpe:2.3:a:redhat:wildfly:*:*:*:*:*:*:*:* | 14.0.0 (excluding) |
To consult the complete list of CPE names with products and versions, see this page
References to Advisories, Solutions, and Tools
- https://access.redhat.com/errata/RHSA-2018:3527
- https://access.redhat.com/errata/RHSA-2018:3528
- https://access.redhat.com/errata/RHSA-2018:3529
- https://access.redhat.com/errata/RHSA-2018:3595
- https://bugzilla.redhat.com/show_bug.cgi?id=CVE-2018-14627
- https://issues.jboss.org/browse/WFLY-9107
- https://security.netapp.com/advisory/ntap-20181221-0002/



