CVE-2018-14627

Severity CVSS v4.0:
Pending analysis
Type:
CWE-319 Cleartext Transmission of Sensitive Information
Publication date:
04/09/2018
Last modified:
03/10/2019

Description

The IIOP OpenJDK Subsystem in WildFly before version 14.0.0 does not honour configuration when SSL transport is required. Servers before this version that are configured with the following setting allow clients to create plaintext connections:

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:redhat:wildfly:*:*:*:*:*:*:*:* 14.0.0 (excluding)