9.1

CVE-2019-14887

A flaw was found when an OpenSSL security provider is used with Wildfly, the 'enabled-protocols' value in the Wildfly configuration isn't honored. An attacker could target the traffic sent from Wildfly and downgrade the connection to a weaker version of TLS, potentially breaking the encryption. This could lead to a leak of the data being passed over the network. Wildfly version 7.2.0.GA, 7.2.3.GA and 7.2.5.CR2 are believed to be vulnerable.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Redhat ≫ Jboss Data Grid Version 7.0.0
Redhat ≫ Jboss Fuse Version 7.0.0
Redhat ≫ Single Sign-on Version 7.0
Redhat ≫ Wildfly Version 7.2.0 Update general_availability
Redhat ≫ Wildfly Version 7.2.3 Update general_availability
Redhat ≫ Wildfly Version 7.2.5 Update cr2
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 1.1% 0.623
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
NIST 9.1 3.9 5.2
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N
NIST 6.4 10 4.9
AV:N/AC:L/Au:N/C:P/I:P/A:N
RedHat 7.4 2.2 5.2
CVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:N
CWE-757 Selection of Less-Secure Algorithm During Negotiation ('Algorithm Downgrade')

A protocol or its implementation supports interaction between multiple actors and allows those actors to negotiate which algorithm should be used as a protection mechanism such as encryption or authentication, but it does not select the strongest algorithm that is available to both parties.

https://bugzilla.redhat.com/show_bug.cgi?id=CVE-2019-14887
Vendor Advisory
Issue Tracking
https://issues.redhat.com/browse/JBEAP-17965
Permissions Required
https://security.netapp.com/advisory/ntap-20200327-0007/
Third Party Advisory