CVE-2018-14627 Vulnerability Details
/
/
/
CVE-2018-14627 Metadata Quick Info
CVE Published: 04/09/2018 |
CVE Updated: 05/08/2024 |
CVE Year: 2018
Source: redhat |
Vendor: [UNKNOWN] |
Product: JBoss/WildFly
Status : PUBLISHED
CVE-2018-14627 Description
The IIOP OpenJDK Subsystem in WildFly before version 14.0.0 does not honour configuration when SSL transport is required. Servers before this version that are configured with the following setting allow clients to create plaintext connections:
Metrics
CVSS Version: 3.1 |
Base Score: n/a
Vector: n/a
l➤ Exploitability Metrics:
Attack Vector (AV)*
Attack Complexity (AC)*
Privileges Required (PR)*
User Interaction (UI)*
Scope (S)*
l➤ Impact Metrics:
Confidentiality Impact (C)*
Integrity Impact (I)*
Availability Impact (A)*
Weakness Enumeration (CWE)
CWE-ID: CWE-319
CWE Name: CWE-319
Source: [UNKNOWN]
Common Attack Pattern Enumeration and Classification (CAPEC)
CAPEC-ID:
CAPEC Description:
Source: NVD (National Vulnerability Database).