{"api_version":"1","generated_at":"2026-07-23T08:40:45+00:00","cve":"CVE-2018-14627","urls":{"html":"https://cve.report/CVE-2018-14627","api":"https://cve.report/api/cve/CVE-2018-14627.json","docs":"https://cve.report/api","cve_org":"https://www.cve.org/CVERecord?id=CVE-2018-14627","nvd":"https://nvd.nist.gov/vuln/detail/CVE-2018-14627"},"summary":{"title":"CVE-2018-14627","description":"The IIOP OpenJDK Subsystem in WildFly before version 14.0.0 does not honour configuration when SSL transport is required. Servers before this version that are configured with the following setting allow clients to create plaintext connections: <transport-config confidentiality=\"required\" trust-in-target=\"supported\"/>","state":"PUBLIC","assigner":"secalert@redhat.com","published_at":"2018-09-04 12:29:00","updated_at":"2019-10-03 00:03:00"},"problem_types":["CWE-319"],"metrics":[],"references":[{"url":"https://access.redhat.com/errata/RHSA-2018:3528","name":"RHSA-2018:3528","refsource":"REDHAT","tags":["Third Party Advisory"],"title":"Red Hat Customer Portal","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"https://access.redhat.com/errata/RHSA-2018:3529","name":"RHSA-2018:3529","refsource":"REDHAT","tags":["Third Party Advisory"],"title":"Red Hat Customer Portal","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"https://issues.jboss.org/browse/WFLY-9107","name":"https://issues.jboss.org/browse/WFLY-9107","refsource":"CONFIRM","tags":["Third Party Advisory"],"title":"[WFLY-9107] Block non-SSL IIOP port when SSL transport is required - Red Hat Issue Tracker","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"https://bugzilla.redhat.com/show_bug.cgi?id=CVE-2018-14627","name":"https://bugzilla.redhat.com/show_bug.cgi?id=CVE-2018-14627","refsource":"CONFIRM","tags":["Issue Tracking","Patch","Third Party Advisory"],"title":"1624664 – (CVE-2018-14627) CVE-2018-14627 JBoss/WildFly: iiop does not honour strict transport confidentiality","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"https://security.netapp.com/advisory/ntap-20181221-0002/","name":"https://security.netapp.com/advisory/ntap-20181221-0002/","refsource":"CONFIRM","tags":[],"title":"CVE-2018-14627 Wildfly Vulnerability in NetApp Products | NetApp Product Security","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"https://access.redhat.com/errata/RHSA-2018:3527","name":"RHSA-2018:3527","refsource":"REDHAT","tags":["Third Party Advisory"],"title":"Red Hat Customer Portal","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"https://access.redhat.com/errata/RHSA-2018:3595","name":"RHSA-2018:3595","refsource":"REDHAT","tags":["Third Party Advisory"],"title":"Red Hat Customer Portal","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"https://www.cve.org/CVERecord?id=CVE-2018-14627","name":"CVE Program record","refsource":"CVE.ORG","tags":["canonical"]},{"url":"https://nvd.nist.gov/vuln/detail/CVE-2018-14627","name":"NVD vulnerability detail","refsource":"NVD","tags":["canonical","analysis"]}],"affected":[],"timeline":[],"solutions":[],"workarounds":[],"exploits":[],"credits":[],"nvd_cpes":[{"cve_year":"2018","cve_id":"14627","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"redhat","cpe5":"wildfly","cpe6":"*","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"},{"cve_year":"2018","cve_id":"14627","vulnerable":"1","versionEndIncluding":"1","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"redhat","cpe5":"wildfly","cpe6":"*","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"}],"vendor_comments":[],"enrichments":{"kev":null,"epss":null,"legacy_qids":[]},"source_records":{"cve_program":{"CVE_data_meta":{"ASSIGNER":"secalert@redhat.com","ID":"CVE-2018-14627","STATE":"PUBLIC"},"affects":{"vendor":{"vendor_data":[{"product":{"product_data":[{"product_name":"JBoss/WildFly","version":{"version_data":[{"version_value":"14.0.0"}]}}]},"vendor_name":"[UNKNOWN]"}]}},"data_format":"MITRE","data_type":"CVE","data_version":"4.0","description":{"description_data":[{"lang":"eng","value":"The IIOP OpenJDK Subsystem in WildFly before version 14.0.0 does not honour configuration when SSL transport is required. Servers before this version that are configured with the following setting allow clients to create plaintext connections: <transport-config confidentiality=\"required\" trust-in-target=\"supported\"/>"}]},"impact":{"cvss":[[{"vectorString":"5.3/CVSS:3.0/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:N/A:N","version":"3.0"}]]},"problemtype":{"problemtype_data":[{"description":[{"lang":"eng","value":"CWE-319"}]}]},"references":{"reference_data":[{"name":"https://bugzilla.redhat.com/show_bug.cgi?id=CVE-2018-14627","refsource":"CONFIRM","url":"https://bugzilla.redhat.com/show_bug.cgi?id=CVE-2018-14627"},{"name":"RHSA-2018:3528","refsource":"REDHAT","url":"https://access.redhat.com/errata/RHSA-2018:3528"},{"name":"RHSA-2018:3527","refsource":"REDHAT","url":"https://access.redhat.com/errata/RHSA-2018:3527"},{"name":"https://issues.jboss.org/browse/WFLY-9107","refsource":"CONFIRM","url":"https://issues.jboss.org/browse/WFLY-9107"},{"name":"https://security.netapp.com/advisory/ntap-20181221-0002/","refsource":"CONFIRM","url":"https://security.netapp.com/advisory/ntap-20181221-0002/"},{"name":"RHSA-2018:3595","refsource":"REDHAT","url":"https://access.redhat.com/errata/RHSA-2018:3595"},{"name":"RHSA-2018:3529","refsource":"REDHAT","url":"https://access.redhat.com/errata/RHSA-2018:3529"}]}},"nvd":{"publishedDate":"2018-09-04 12:29:00","lastModifiedDate":"2019-10-03 00:03:00","problem_types":["CWE-319"],"metrics":{"baseMetricV3":{"cvssV3":{"version":"3.0","vectorString":"CVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N","attackVector":"NETWORK","attackComplexity":"HIGH","privilegesRequired":"NONE","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"HIGH","integrityImpact":"NONE","availabilityImpact":"NONE","baseScore":5.9,"baseSeverity":"MEDIUM"},"exploitabilityScore":2.2,"impactScore":3.6},"baseMetricV2":{"cvssV2":{"version":"2.0","vectorString":"AV:N/AC:M/Au:N/C:P/I:N/A:N","accessVector":"NETWORK","accessComplexity":"MEDIUM","authentication":"NONE","confidentialityImpact":"PARTIAL","integrityImpact":"NONE","availabilityImpact":"NONE","baseScore":4.3},"severity":"MEDIUM","exploitabilityScore":8.6,"impactScore":2.9,"acInsufInfo":false,"obtainAllPrivilege":false,"obtainUserPrivilege":false,"obtainOtherPrivilege":false,"userInteractionRequired":false}},"configurations":{"CVE_data_version":"4.0","nodes":[{"operator":"OR","children":[],"cpe_match":[{"vulnerable":true,"cpe23Uri":"cpe:2.3:a:redhat:wildfly:*:*:*:*:*:*:*:*","versionEndExcluding":"14.0.0","cpe_name":[]}]}]}},"legacy_mitre":{"record":{"CveYear":"2018","CveId":"14627","Ordinal":"131335","Title":"CVE-2018-14627","CVE":"CVE-2018-14627","Year":"2018"},"notes":[{"CveYear":"2018","CveId":"14627","Ordinal":"1","NoteData":"The IIOP OpenJDK Subsystem in WildFly before version 14.0.0 does not honour configuration when SSL transport is required. Servers before this version that are configured with the following setting allow clients to create plaintext connections: <transport-config confidentiality=\"required\" trust-in-target=\"supported\"/>","Type":"Description","Title":null},{"CveYear":"2018","CveId":"14627","Ordinal":"2","NoteData":"2018-09-04","Type":"Other","Title":"Published"},{"CveYear":"2018","CveId":"14627","Ordinal":"3","NoteData":"2018-12-22","Type":"Other","Title":"Modified"}]}}}