CVE-2018-14627
JBoss/WildFly: iiop does not honour strict transport confidentiality
Severity Score
Exploit Likelihood
Affected Versions
Public Exploits
0Exploited in Wild
-Decision
Descriptions
The IIOP OpenJDK Subsystem in WildFly before version 14.0.0 does not honour configuration when SSL transport is required. Servers before this version that are configured with the following setting allow clients to create plaintext connections: <transport-config confidentiality="required" trust-in-target="supported"/>
El subsistema IIOP OpenJDK en WildFly en versiones anteriores a la 14.0.0 no cumple con al configuración cuando se requiere transporte SSL. Los servidores con versiones anteriores a ésta que estén configurados con las siguientes opciones permiten que los clientes creen conexiones en texto plano:
Red Hat Single Sign-On 7.2 is a standalone server, based on the Keycloak project, that provides authentication and standards-based single sign-on capabilities for web and mobile applications. This release of Red Hat Single Sign-On 7.2.5 serves as a replacement for Red Hat Single Sign-On 7.2.4, and includes bug fixes and enhancements, which are documented in the Release Notes document linked to in the References. Issues addressed include a cross site scripting vulnerability.
CVSS Scores
SSVC
- Decision:-
Timeline
- 2018-07-27 CVE Reserved
- 2018-09-04 CVE Published
- 2024-08-05 CVE Updated
- 2025-03-30 EPSS Updated
- ---------- Exploited in Wild
- ---------- KEV Due Date
- ---------- First Exploit
CWE
- CWE-319: Cleartext Transmission of Sensitive Information
CAPEC
References (9)
URL | Tag | Source |
---|---|---|
https://issues.jboss.org/browse/WFLY-9107 | Third Party Advisory | |
https://security.netapp.com/advisory/ntap-20181221-0002 | X_refsource_confirm |
|
URL | Date | SRC |
---|
URL | Date | SRC |
---|---|---|
https://bugzilla.redhat.com/show_bug.cgi?id=CVE-2018-14627 | 2019-10-03 |
URL | Date | SRC |
---|---|---|
https://access.redhat.com/errata/RHSA-2018:3527 | 2019-10-03 | |
https://access.redhat.com/errata/RHSA-2018:3528 | 2019-10-03 | |
https://access.redhat.com/errata/RHSA-2018:3529 | 2019-10-03 | |
https://access.redhat.com/errata/RHSA-2018:3595 | 2019-10-03 | |
https://access.redhat.com/security/cve/CVE-2018-14627 | 2018-11-13 | |
https://bugzilla.redhat.com/show_bug.cgi?id=1624664 | 2018-11-13 |