Vulnerabilities
Vulnerable Software
Redhat:  >> Wildfly  >> 10.1.2  Security Vulnerabilities
The IIOP OpenJDK Subsystem in WildFly before version 14.0.0 does not honour configuration when SSL transport is required. Servers before this version that are configured with the following setting allow clients to create plaintext connections: <transport-config confidentiality="required" trust-in-target="supported"/>
CVSS Score
5.3
EPSS Score
0.011
Published
2018-09-04
An issue was discovered in WildFly 10.1.2.Final. In the case of a default installation without a security realm reference, an attacker can successfully access the server without authentication. NOTE: the Security Realms documentation in the product's Admin Guide indicates that "without a security realm reference" implies "effectively unsecured." The vendor explicitly supports these unsecured configurations because they have valid use cases during development
CVSS Score
9.8
EPSS Score
0.018
Published
2018-05-09


Contact Us

Shodan ® - All rights reserved