SOC status:Duty analyst on shift

UK Cyber Defence
VulnerabilityModified

CVE-2018-14627

Servers before this version that are configured with the following setting allow clients to create plaintext connections: <transport-config confidentiality="required" trust-in-target="supported"/>

MEDIUM 5.9EPSS 1.11%

Does this matter?

Lower severity and a low EPSS score (1.11%). Track it; it rarely justifies an emergency change on its own.

Description

The IIOP OpenJDK Subsystem in WildFly before version 14.0.0 does not honour configuration when SSL transport is required. Servers before this version that are configured with the following setting allow clients to create plaintext connections: <transport-config confidentiality="required" trust-in-target="supported"/>

CVSS 3.0
5.9 MEDIUMCVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N
EPSS
1.11% probability · 64th percentile
CISA KEV
Not listed
Weakness
CWE-319
Affected
redhat/wildfly
Source
secalert@redhat.com

Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.