7.5

CVE-2022-1278

A flaw was found in WildFly, where an attacker can see deployment names, endpoints, and any other data the trace payload may contain.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Redhat ≫ Wildfly Version < 27.0.0
Redhat ≫ Amq Version 2.0
Redhat ≫ Amq Online Version -
Redhat ≫ Integration Camel K Version -
Redhat ≫ Jboss A-mq Version 7
Redhat ≫ Single Sign-on Version 7.0
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 0.78% 0.53
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
NIST 7.5 3.9 3.6
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
CWE-1188 Initialization of a Resource with an Insecure Default

The product initializes or sets a resource with a default that is intended to be changed by the product's installer, administrator, or maintainer, but the default is not secure.

https://bugzilla.redhat.com/show_bug.cgi?id=2073401
Vendor Advisory
Issue Tracking