PT-2018-10051 · Red Hat · Wildfly

Bourbon Jean-Marie

+3

·

Published

2018-05-09

·

Updated

2024-08-05

·

CVE-2018-10683

CVSS v3.1

9.8

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions WildFly version 10.1.2.Final
Description An issue was discovered where an attacker can access the server without authentication in the case of a default installation without a security realm reference. This is because the configuration is effectively unsecured, as indicated by the Security Realms documentation in the product's Admin Guide. The vendor supports these unsecured configurations due to valid use cases during development.
Recommendations For WildFly version 10.1.2.Final, consider configuring a security realm reference to secure the server and prevent unauthorized access. As a temporary workaround, restrict access to the server to minimize the risk of exploitation.

Exploit

Fix

Improper Authentication

Weakness Enumeration

Related Identifiers

CVE-2018-10683

Affected Products

Wildfly