CVE Vulnerabilities

CVE-2018-14627

Cleartext Transmission of Sensitive Information

Published: Sep 04, 2018 | Modified: Nov 21, 2024
CVSS 3.x
5.9
MEDIUM
Source:
NVD
CVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N
CVSS 2.x
4.3 MEDIUM
AV:N/AC:M/Au:N/C:P/I:N/A:N
RedHat/V2
RedHat/V3
5.3 MODERATE
CVSS:3.0/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:N/A:N
Ubuntu
root.io logo minimus.io logo echo.ai logo

The IIOP OpenJDK Subsystem in WildFly before version 14.0.0 does not honour configuration when SSL transport is required. Servers before this version that are configured with the following setting allow clients to create plaintext connections:

Weakness

The product transmits sensitive or security-critical data in cleartext in a communication channel that can be sniffed by unauthorized actors.

Affected Software

NameVendorStart VersionEnd Version
WildflyRedhat*14.0.0 (excluding)
Red Hat JBoss EAP 7.1RedHatwildfly-iiop-openjdk*
Red Hat JBoss Enterprise Application Platform 7.1 for RHEL 6RedHateap7-activemq-artemis-0:1.5.5.014-1.redhat_00001.1.ep7.el6*
Red Hat JBoss Enterprise Application Platform 7.1 for RHEL 6RedHateap7-elytron-web-0:1.0.2-1.Final_redhat_00001.1.ep7.el6*
Red Hat JBoss Enterprise Application Platform 7.1 for RHEL 6RedHateap7-glassfish-jsf-0:2.2.13-7.SP6_redhat_00001.1.ep7.el6*
Red Hat JBoss Enterprise Application Platform 7.1 for RHEL 6RedHateap7-hibernate-0:5.1.16-1.Final_redhat_00001.1.ep7.el6*
Red Hat JBoss Enterprise Application Platform 7.1 for RHEL 6RedHateap7-ironjacamar-0:1.4.11-1.Final_redhat_00001.1.ep7.el6*
Red Hat JBoss Enterprise Application Platform 7.1 for RHEL 6RedHateap7-jboss-marshalling-0:2.0.6-1.Final_redhat_00001.1.ep7.el6*
Red Hat JBoss Enterprise Application Platform 7.1 for RHEL 6RedHateap7-jboss-modules-0:1.6.5-1.Final_redhat_00001.1.ep7.el6*
Red Hat JBoss Enterprise Application Platform 7.1 for RHEL 6RedHateap7-jboss-server-migration-0:1.0.7-1.Final_redhat_00001.1.ep7.el6*
Red Hat JBoss Enterprise Application Platform 7.1 for RHEL 6RedHateap7-jboss-vfs-0:3.2.13-1.Final_redhat_1.1.ep7.el6*
Red Hat JBoss Enterprise Application Platform 7.1 for RHEL 6RedHateap7-jbossws-common-0:3.1.6-1.Final_redhat_00001.1.ep7.el6*
Red Hat JBoss Enterprise Application Platform 7.1 for RHEL 6RedHateap7-jbossws-cxf-0:5.1.11-1.Final_redhat_00001.1.ep7.el6*
Red Hat JBoss Enterprise Application Platform 7.1 for RHEL 6RedHateap7-jboss-xnio-base-0:3.5.6-1.Final_redhat_00001.1.ep7.el6*
Red Hat JBoss Enterprise Application Platform 7.1 for RHEL 6RedHateap7-log4j-jboss-logmanager-0:1.1.6-1.Final_redhat_00001.1.ep7.el6*
Red Hat JBoss Enterprise Application Platform 7.1 for RHEL 6RedHateap7-picketbox-0:5.0.3-2.Final_redhat_3.1.ep7.el6*
Red Hat JBoss Enterprise Application Platform 7.1 for RHEL 6RedHateap7-picketlink-bindings-0:2.5.5-14.SP12_redhat_2.1.ep7.el6*
Red Hat JBoss Enterprise Application Platform 7.1 for RHEL 6RedHateap7-picketlink-federation-0:2.5.5-14.SP12_redhat_2.1.ep7.el6*
Red Hat JBoss Enterprise Application Platform 7.1 for RHEL 6RedHateap7-undertow-0:1.4.18-8.SP9_redhat_00001.1.ep7.el6*
Red Hat JBoss Enterprise Application Platform 7.1 for RHEL 6RedHateap7-undertow-jastow-0:2.0.6-1.Final_redhat_00001.1.ep7.el6*
Red Hat JBoss Enterprise Application Platform 7.1 for RHEL 6RedHateap7-wildfly-0:7.1.5-4.GA_redhat_00002.1.ep7.el6*
Red Hat JBoss Enterprise Application Platform 7.1 for RHEL 6RedHateap7-wildfly-client-config-0:1.0.1-1.Final_redhat_00001.1.ep7.el6*
Red Hat JBoss Enterprise Application Platform 7.1 for RHEL 6RedHateap7-wildfly-elytron-0:1.1.11-1.Final_redhat_00001.1.ep7.el6*
Red Hat JBoss Enterprise Application Platform 7.1 for RHEL 6RedHateap7-wildfly-elytron-tool-0:1.0.8-1.Final_redhat_00001.1.ep7.el6*
Red Hat JBoss Enterprise Application Platform 7.1 for RHEL 6RedHateap7-wildfly-javadocs-0:7.1.5-2.GA_redhat_00002.1.ep7.el6*
Red Hat JBoss Enterprise Application Platform 7.1 for RHEL 6RedHateap7-wildfly-openssl-0:1.0.6-2.Final_redhat_2.1.ep7.el6*
Red Hat JBoss Enterprise Application Platform 7.1 for RHEL 6RedHateap7-wildfly-openssl-linux-0:1.0.6-15.Final_redhat_2.1.ep7.el6*
Red Hat JBoss Enterprise Application Platform 7.1 for RHEL 7RedHateap7-activemq-artemis-0:1.5.5.014-1.redhat_00001.1.ep7.el7*
Red Hat JBoss Enterprise Application Platform 7.1 for RHEL 7RedHateap7-elytron-web-0:1.0.2-1.Final_redhat_00001.1.ep7.el7*
Red Hat JBoss Enterprise Application Platform 7.1 for RHEL 7RedHateap7-glassfish-jsf-0:2.2.13-7.SP6_redhat_00001.1.ep7.el7*
Red Hat JBoss Enterprise Application Platform 7.1 for RHEL 7RedHateap7-hibernate-0:5.1.16-1.Final_redhat_00001.1.ep7.el7*
Red Hat JBoss Enterprise Application Platform 7.1 for RHEL 7RedHateap7-ironjacamar-0:1.4.11-1.Final_redhat_00001.1.ep7.el7*
Red Hat JBoss Enterprise Application Platform 7.1 for RHEL 7RedHateap7-jboss-marshalling-0:2.0.6-1.Final_redhat_00001.1.ep7.el7*
Red Hat JBoss Enterprise Application Platform 7.1 for RHEL 7RedHateap7-jboss-modules-0:1.6.5-1.Final_redhat_00001.1.ep7.el7*
Red Hat JBoss Enterprise Application Platform 7.1 for RHEL 7RedHateap7-jboss-server-migration-0:1.0.7-1.Final_redhat_00001.1.ep7.el7*
Red Hat JBoss Enterprise Application Platform 7.1 for RHEL 7RedHateap7-jboss-vfs-0:3.2.13-1.Final_redhat_1.1.ep7.el7*
Red Hat JBoss Enterprise Application Platform 7.1 for RHEL 7RedHateap7-jbossws-common-0:3.1.6-1.Final_redhat_00001.1.ep7.el7*
Red Hat JBoss Enterprise Application Platform 7.1 for RHEL 7RedHateap7-jbossws-cxf-0:5.1.11-1.Final_redhat_00001.1.ep7.el7*
Red Hat JBoss Enterprise Application Platform 7.1 for RHEL 7RedHateap7-jboss-xnio-base-0:3.5.6-1.Final_redhat_00001.1.ep7.el7*
Red Hat JBoss Enterprise Application Platform 7.1 for RHEL 7RedHateap7-log4j-jboss-logmanager-0:1.1.6-1.Final_redhat_00001.1.ep7.el7*
Red Hat JBoss Enterprise Application Platform 7.1 for RHEL 7RedHateap7-picketbox-0:5.0.3-2.Final_redhat_3.1.ep7.el7*
Red Hat JBoss Enterprise Application Platform 7.1 for RHEL 7RedHateap7-picketlink-bindings-0:2.5.5-14.SP12_redhat_2.1.ep7.el7*
Red Hat JBoss Enterprise Application Platform 7.1 for RHEL 7RedHateap7-picketlink-federation-0:2.5.5-14.SP12_redhat_2.1.ep7.el7*
Red Hat JBoss Enterprise Application Platform 7.1 for RHEL 7RedHateap7-undertow-0:1.4.18-8.SP9_redhat_00001.1.ep7.el7*
Red Hat JBoss Enterprise Application Platform 7.1 for RHEL 7RedHateap7-undertow-jastow-0:2.0.6-1.Final_redhat_00001.1.ep7.el7*
Red Hat JBoss Enterprise Application Platform 7.1 for RHEL 7RedHateap7-wildfly-0:7.1.5-4.GA_redhat_00002.1.ep7.el7*
Red Hat JBoss Enterprise Application Platform 7.1 for RHEL 7RedHateap7-wildfly-client-config-0:1.0.1-1.Final_redhat_00001.1.ep7.el7*
Red Hat JBoss Enterprise Application Platform 7.1 for RHEL 7RedHateap7-wildfly-elytron-0:1.1.11-1.Final_redhat_00001.1.ep7.el7*
Red Hat JBoss Enterprise Application Platform 7.1 for RHEL 7RedHateap7-wildfly-elytron-tool-0:1.0.8-1.Final_redhat_00001.1.ep7.el7*
Red Hat JBoss Enterprise Application Platform 7.1 for RHEL 7RedHateap7-wildfly-javadocs-0:7.1.5-2.GA_redhat_00002.1.ep7.el7*
Red Hat JBoss Enterprise Application Platform 7.1 for RHEL 7RedHateap7-wildfly-openssl-0:1.0.6-2.Final_redhat_2.1.ep7.el7*
Red Hat JBoss Enterprise Application Platform 7.1 for RHEL 7RedHateap7-wildfly-openssl-linux-0:1.0.6-15.Final_redhat_2.1.ep7.el7*
Red Hat Single Sign-On 7.2.5 zipRedHatwildfly-iiop-openjdk*

Potential Mitigations

References