PT-2020-5188 · Openssl+1 · Openssl+1
Kunjan Rathod
·
Published
2020-03-16
·
Updated
2021-11-02
·
CVE-2019-14887
CVSS v2.0
9.4
Critical
| Vector | AV:N/AC:L/Au:N/C:C/I:C/A:N |
Name of the Vulnerable Software and Affected Versions
Wildfly versions 7.2.0.GA through 7.2.5.CR2
Description
A flaw was found when an OpenSSL security provider is used with Wildfly, where the 'enabled-protocols' value in the Wildfly configuration isn't honored. This could allow an attacker to target the traffic sent from Wildfly and downgrade the connection to a weaker version of TLS, potentially breaking the encryption and leading to a leak of the data being passed over the network.
Recommendations
For Wildfly version 7.2.0.GA, update to a fixed version to resolve the issue.
For Wildfly version 7.2.3.GA, update to a fixed version to resolve the issue.
For Wildfly version 7.2.5.CR2, update to a fixed version to resolve the issue.
As a temporary workaround, consider restricting the use of the OpenSSL security provider until a patch is available.
Restrict access to the vulnerable configuration to minimize the risk of exploitation.
Fix
Inadequate Encryption Strength
Improper Handling of Exceptional Conditions
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Openssl
Wildfly