The IIOP OpenJDK Subsystem in WildFly before version 14.0.0 does not honour configuration when SSL transport is required. Servers before this version that are configured with the following setting allow clients to create plaintext connections: <transport-config confidentiality="required" trust-in-target="supported"/>
History

No history.

cve-icon MITRE Information

Status: PUBLISHED

Assigner: redhat

Published: 2018-09-04T12:00:00

Updated: 2018-12-22T10:57:01

Reserved: 2018-07-27T00:00:00


Link: CVE-2018-14627

JSON object: View

cve-icon NVD Information

Status : Modified

Published: 2018-09-04T12:29:00.623

Modified: 2019-10-03T00:03:26.223


Link: CVE-2018-14627

JSON object: View

cve-icon Redhat Information

No data.

CWE