The IIOP OpenJDK Subsystem in WildFly before version 14.0.0 does...
Vulnerability Description
The IIOP OpenJDK Subsystem in WildFly before version 14.0.0 does not honour configuration when SSL transport is required. Servers before this version that are configured with the following setting allow clients to create plaintext connections: <transport-config confidentiality="required" trust-in-target="supported"/>
Impact Analysis
Refer to official advisory for detailed impact metrics.
Remediation
Ensure systems are updated to the latest vendor-supplied patch levels.
Am I Vulnerable?
Launch our assessment wizard to check if your infrastructure is exposed to • CVE-2018-14627
Credits & Attribution
No credits recorded in the NVD database.
References
- https://bugzilla.redhat.com/show_bug.cgi?id=CVE-2018-14627
- https://access.redhat.com/errata/RHSA-2018:3528
- https://access.redhat.com/errata/RHSA-2018:3527
- https://issues.jboss.org/browse/WFLY-9107
- https://security.netapp.com/advisory/ntap-20181221-0002/
- https://access.redhat.com/errata/RHSA-2018:3595
- https://access.redhat.com/errata/RHSA-2018:3529
More from [UNKNOWN]
View All →Affected Vendor
[UNKNOWN]
View all reports →