CVE Vulnerabilities

CVE-2018-14627

Cleartext Transmission of Sensitive Information

Published: Sep 04, 2018 | Modified: Nov 21, 2024
CVSS 3.x
5.9
MEDIUM
Source:
NVD
CVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N
CVSS 2.x
4.3 MEDIUM
AV:N/AC:M/Au:N/C:P/I:N/A:N
RedHat/V2
RedHat/V3
5.3 MODERATE
CVSS:3.0/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:N/A:N
Ubuntu

The IIOP OpenJDK Subsystem in WildFly before version 14.0.0 does not honour configuration when SSL transport is required. Servers before this version that are configured with the following setting allow clients to create plaintext connections:

Weakness

The product transmits sensitive or security-critical data in cleartext in a communication channel that can be sniffed by unauthorized actors.

Affected Software

Name Vendor Start Version End Version
Wildfly Redhat * 14.0.0 (excluding)
Red Hat JBoss EAP 7.1 RedHat wildfly-iiop-openjdk *
Red Hat JBoss Enterprise Application Platform 7.1 for RHEL 6 RedHat eap7-activemq-artemis-0:1.5.5.014-1.redhat_00001.1.ep7.el6 *
Red Hat JBoss Enterprise Application Platform 7.1 for RHEL 6 RedHat eap7-elytron-web-0:1.0.2-1.Final_redhat_00001.1.ep7.el6 *
Red Hat JBoss Enterprise Application Platform 7.1 for RHEL 6 RedHat eap7-glassfish-jsf-0:2.2.13-7.SP6_redhat_00001.1.ep7.el6 *
Red Hat JBoss Enterprise Application Platform 7.1 for RHEL 6 RedHat eap7-hibernate-0:5.1.16-1.Final_redhat_00001.1.ep7.el6 *
Red Hat JBoss Enterprise Application Platform 7.1 for RHEL 6 RedHat eap7-ironjacamar-0:1.4.11-1.Final_redhat_00001.1.ep7.el6 *
Red Hat JBoss Enterprise Application Platform 7.1 for RHEL 6 RedHat eap7-jboss-marshalling-0:2.0.6-1.Final_redhat_00001.1.ep7.el6 *
Red Hat JBoss Enterprise Application Platform 7.1 for RHEL 6 RedHat eap7-jboss-modules-0:1.6.5-1.Final_redhat_00001.1.ep7.el6 *
Red Hat JBoss Enterprise Application Platform 7.1 for RHEL 6 RedHat eap7-jboss-server-migration-0:1.0.7-1.Final_redhat_00001.1.ep7.el6 *
Red Hat JBoss Enterprise Application Platform 7.1 for RHEL 6 RedHat eap7-jboss-vfs-0:3.2.13-1.Final_redhat_1.1.ep7.el6 *
Red Hat JBoss Enterprise Application Platform 7.1 for RHEL 6 RedHat eap7-jbossws-common-0:3.1.6-1.Final_redhat_00001.1.ep7.el6 *
Red Hat JBoss Enterprise Application Platform 7.1 for RHEL 6 RedHat eap7-jbossws-cxf-0:5.1.11-1.Final_redhat_00001.1.ep7.el6 *
Red Hat JBoss Enterprise Application Platform 7.1 for RHEL 6 RedHat eap7-jboss-xnio-base-0:3.5.6-1.Final_redhat_00001.1.ep7.el6 *
Red Hat JBoss Enterprise Application Platform 7.1 for RHEL 6 RedHat eap7-log4j-jboss-logmanager-0:1.1.6-1.Final_redhat_00001.1.ep7.el6 *
Red Hat JBoss Enterprise Application Platform 7.1 for RHEL 6 RedHat eap7-picketbox-0:5.0.3-2.Final_redhat_3.1.ep7.el6 *
Red Hat JBoss Enterprise Application Platform 7.1 for RHEL 6 RedHat eap7-picketlink-bindings-0:2.5.5-14.SP12_redhat_2.1.ep7.el6 *
Red Hat JBoss Enterprise Application Platform 7.1 for RHEL 6 RedHat eap7-picketlink-federation-0:2.5.5-14.SP12_redhat_2.1.ep7.el6 *
Red Hat JBoss Enterprise Application Platform 7.1 for RHEL 6 RedHat eap7-undertow-0:1.4.18-8.SP9_redhat_00001.1.ep7.el6 *
Red Hat JBoss Enterprise Application Platform 7.1 for RHEL 6 RedHat eap7-undertow-jastow-0:2.0.6-1.Final_redhat_00001.1.ep7.el6 *
Red Hat JBoss Enterprise Application Platform 7.1 for RHEL 6 RedHat eap7-wildfly-0:7.1.5-4.GA_redhat_00002.1.ep7.el6 *
Red Hat JBoss Enterprise Application Platform 7.1 for RHEL 6 RedHat eap7-wildfly-client-config-0:1.0.1-1.Final_redhat_00001.1.ep7.el6 *
Red Hat JBoss Enterprise Application Platform 7.1 for RHEL 6 RedHat eap7-wildfly-elytron-0:1.1.11-1.Final_redhat_00001.1.ep7.el6 *
Red Hat JBoss Enterprise Application Platform 7.1 for RHEL 6 RedHat eap7-wildfly-elytron-tool-0:1.0.8-1.Final_redhat_00001.1.ep7.el6 *
Red Hat JBoss Enterprise Application Platform 7.1 for RHEL 6 RedHat eap7-wildfly-javadocs-0:7.1.5-2.GA_redhat_00002.1.ep7.el6 *
Red Hat JBoss Enterprise Application Platform 7.1 for RHEL 6 RedHat eap7-wildfly-openssl-0:1.0.6-2.Final_redhat_2.1.ep7.el6 *
Red Hat JBoss Enterprise Application Platform 7.1 for RHEL 6 RedHat eap7-wildfly-openssl-linux-0:1.0.6-15.Final_redhat_2.1.ep7.el6 *
Red Hat JBoss Enterprise Application Platform 7.1 for RHEL 7 RedHat eap7-activemq-artemis-0:1.5.5.014-1.redhat_00001.1.ep7.el7 *
Red Hat JBoss Enterprise Application Platform 7.1 for RHEL 7 RedHat eap7-elytron-web-0:1.0.2-1.Final_redhat_00001.1.ep7.el7 *
Red Hat JBoss Enterprise Application Platform 7.1 for RHEL 7 RedHat eap7-glassfish-jsf-0:2.2.13-7.SP6_redhat_00001.1.ep7.el7 *
Red Hat JBoss Enterprise Application Platform 7.1 for RHEL 7 RedHat eap7-hibernate-0:5.1.16-1.Final_redhat_00001.1.ep7.el7 *
Red Hat JBoss Enterprise Application Platform 7.1 for RHEL 7 RedHat eap7-ironjacamar-0:1.4.11-1.Final_redhat_00001.1.ep7.el7 *
Red Hat JBoss Enterprise Application Platform 7.1 for RHEL 7 RedHat eap7-jboss-marshalling-0:2.0.6-1.Final_redhat_00001.1.ep7.el7 *
Red Hat JBoss Enterprise Application Platform 7.1 for RHEL 7 RedHat eap7-jboss-modules-0:1.6.5-1.Final_redhat_00001.1.ep7.el7 *
Red Hat JBoss Enterprise Application Platform 7.1 for RHEL 7 RedHat eap7-jboss-server-migration-0:1.0.7-1.Final_redhat_00001.1.ep7.el7 *
Red Hat JBoss Enterprise Application Platform 7.1 for RHEL 7 RedHat eap7-jboss-vfs-0:3.2.13-1.Final_redhat_1.1.ep7.el7 *
Red Hat JBoss Enterprise Application Platform 7.1 for RHEL 7 RedHat eap7-jbossws-common-0:3.1.6-1.Final_redhat_00001.1.ep7.el7 *
Red Hat JBoss Enterprise Application Platform 7.1 for RHEL 7 RedHat eap7-jbossws-cxf-0:5.1.11-1.Final_redhat_00001.1.ep7.el7 *
Red Hat JBoss Enterprise Application Platform 7.1 for RHEL 7 RedHat eap7-jboss-xnio-base-0:3.5.6-1.Final_redhat_00001.1.ep7.el7 *
Red Hat JBoss Enterprise Application Platform 7.1 for RHEL 7 RedHat eap7-log4j-jboss-logmanager-0:1.1.6-1.Final_redhat_00001.1.ep7.el7 *
Red Hat JBoss Enterprise Application Platform 7.1 for RHEL 7 RedHat eap7-picketbox-0:5.0.3-2.Final_redhat_3.1.ep7.el7 *
Red Hat JBoss Enterprise Application Platform 7.1 for RHEL 7 RedHat eap7-picketlink-bindings-0:2.5.5-14.SP12_redhat_2.1.ep7.el7 *
Red Hat JBoss Enterprise Application Platform 7.1 for RHEL 7 RedHat eap7-picketlink-federation-0:2.5.5-14.SP12_redhat_2.1.ep7.el7 *
Red Hat JBoss Enterprise Application Platform 7.1 for RHEL 7 RedHat eap7-undertow-0:1.4.18-8.SP9_redhat_00001.1.ep7.el7 *
Red Hat JBoss Enterprise Application Platform 7.1 for RHEL 7 RedHat eap7-undertow-jastow-0:2.0.6-1.Final_redhat_00001.1.ep7.el7 *
Red Hat JBoss Enterprise Application Platform 7.1 for RHEL 7 RedHat eap7-wildfly-0:7.1.5-4.GA_redhat_00002.1.ep7.el7 *
Red Hat JBoss Enterprise Application Platform 7.1 for RHEL 7 RedHat eap7-wildfly-client-config-0:1.0.1-1.Final_redhat_00001.1.ep7.el7 *
Red Hat JBoss Enterprise Application Platform 7.1 for RHEL 7 RedHat eap7-wildfly-elytron-0:1.1.11-1.Final_redhat_00001.1.ep7.el7 *
Red Hat JBoss Enterprise Application Platform 7.1 for RHEL 7 RedHat eap7-wildfly-elytron-tool-0:1.0.8-1.Final_redhat_00001.1.ep7.el7 *
Red Hat JBoss Enterprise Application Platform 7.1 for RHEL 7 RedHat eap7-wildfly-javadocs-0:7.1.5-2.GA_redhat_00002.1.ep7.el7 *
Red Hat JBoss Enterprise Application Platform 7.1 for RHEL 7 RedHat eap7-wildfly-openssl-0:1.0.6-2.Final_redhat_2.1.ep7.el7 *
Red Hat JBoss Enterprise Application Platform 7.1 for RHEL 7 RedHat eap7-wildfly-openssl-linux-0:1.0.6-15.Final_redhat_2.1.ep7.el7 *
Red Hat Single Sign-On 7.2.5 zip RedHat wildfly-iiop-openjdk *

Potential Mitigations

References