Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2018-14627

Опубликовано: 19 июл. 2017
Источник: redhat
CVSS3: 5.3
EPSS Низкий

Описание

The IIOP OpenJDK Subsystem in WildFly before version 14.0.0 does not honour configuration when SSL transport is required. Servers before this version that are configured with the following setting allow clients to create plaintext connections:

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat Decision Manager 7wildfly-iiop-openjdkWill not fix
Red Hat JBoss Data Grid 7wildfly-iiop-openjdkAffected
Red Hat JBoss EAP 7.1wildfly-iiop-openjdkFixedRHSA-2018:352708.11.2018
Red Hat JBoss Enterprise Application Platform 7.1 for RHEL 6eap7-activemq-artemisFixedRHSA-2018:352908.11.2018
Red Hat JBoss Enterprise Application Platform 7.1 for RHEL 6eap7-elytron-webFixedRHSA-2018:352908.11.2018
Red Hat JBoss Enterprise Application Platform 7.1 for RHEL 6eap7-glassfish-jsfFixedRHSA-2018:352908.11.2018
Red Hat JBoss Enterprise Application Platform 7.1 for RHEL 6eap7-hibernateFixedRHSA-2018:352908.11.2018
Red Hat JBoss Enterprise Application Platform 7.1 for RHEL 6eap7-ironjacamarFixedRHSA-2018:352908.11.2018
Red Hat JBoss Enterprise Application Platform 7.1 for RHEL 6eap7-jboss-marshallingFixedRHSA-2018:352908.11.2018
Red Hat JBoss Enterprise Application Platform 7.1 for RHEL 6eap7-jboss-modulesFixedRHSA-2018:352908.11.2018

Показывать по

Дополнительная информация

Статус:

Moderate
Дефект:
CWE-319
https://bugzilla.redhat.com/show_bug.cgi?id=1624664JBoss/WildFly: iiop does not honour strict transport confidentiality

EPSS

Процентиль: 47%
0.0024
Низкий

5.3 Medium

CVSS3

Связанные уязвимости

CVSS3: 5.3
nvd
больше 7 лет назад

The IIOP OpenJDK Subsystem in WildFly before version 14.0.0 does not honour configuration when SSL transport is required. Servers before this version that are configured with the following setting allow clients to create plaintext connections: <transport-config confidentiality="required" trust-in-target="supported"/>

CVSS3: 5.3
debian
больше 7 лет назад

The IIOP OpenJDK Subsystem in WildFly before version 14.0.0 does not h ...

CVSS3: 5.9
github
больше 3 лет назад

The IIOP OpenJDK Subsystem in WildFly before version 14.0.0 does not honour configuration when SSL transport is required. Servers before this version that are configured with the following setting allow clients to create plaintext connections: <transport-config confidentiality="required" trust-in-target="supported"/>

EPSS

Процентиль: 47%
0.0024
Низкий

5.3 Medium

CVSS3