PT-2018-10051 · Red Hat · Wildfly

Bourbon Jean-Marie

+3

·

Publicado

2018-05-09

·

Atualizado

2024-08-05

·

CVE-2018-10683

CVSS v3.1

9.8

Crítica

VetorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions WildFly version 10.1.2.Final
Description An issue was discovered where an attacker can access the server without authentication in the case of a default installation without a security realm reference. This is because the configuration is effectively unsecured, as indicated by the Security Realms documentation in the product's Admin Guide. The vendor supports these unsecured configurations due to valid use cases during development.
Recommendations For WildFly version 10.1.2.Final, consider configuring a security realm reference to secure the server and prevent unauthorized access. As a temporary workaround, restrict access to the server to minimize the risk of exploitation.

Exploit

Correção

Improper Authentication

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

CVE-2018-10683

Produtos afetados

Wildfly