">
The IIOP OpenJDK Subsystem in WildFly before version 14.0.0 does not honour configuration when SSL transport is required. Servers before this version that are configured with the following setting allow clients to create plaintext connections: <transport-config confidentiality="required" trust-in-target="supported"/>
The product transmits sensitive or security-critical data in cleartext in a communication channel that can be sniffed by unauthorized actors.
Link | Tags |
---|---|
https://bugzilla.redhat.com/show_bug.cgi?id=CVE-2018-14627 | issue tracking third party advisory patch |
https://access.redhat.com/errata/RHSA-2018:3528 | third party advisory vendor advisory |
https://access.redhat.com/errata/RHSA-2018:3527 | third party advisory vendor advisory |
https://issues.jboss.org/browse/WFLY-9107 | third party advisory |
https://security.netapp.com/advisory/ntap-20181221-0002/ | |
https://access.redhat.com/errata/RHSA-2018:3595 | third party advisory vendor advisory |
https://access.redhat.com/errata/RHSA-2018:3529 | third party advisory vendor advisory |