PT-2018-10051 · Red Hat · Wildfly
Bourbon Jean-Marie
+3
·
Publicado
2018-05-09
·
Atualizado
2024-08-05
·
CVE-2018-10683
CVSS v3.1
9.8
Crítica
| Vetor | AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
WildFly version 10.1.2.Final
Description
An issue was discovered where an attacker can access the server without authentication in the case of a default installation without a security realm reference. This is because the configuration is effectively unsecured, as indicated by the Security Realms documentation in the product's Admin Guide. The vendor supports these unsecured configurations due to valid use cases during development.
Recommendations
For WildFly version 10.1.2.Final, consider configuring a security realm reference to secure the server and prevent unauthorized access. As a temporary workaround, restrict access to the server to minimize the risk of exploitation.
Exploit
Correção
Improper Authentication
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾
Enumeração de Fraquezas
Identificadores relacionados
Produtos afetados
Wildfly