CVE-2018-10683: Critical severity wildfly vulnerability
DISPUTED An issue was discovered in WildFly 10.1.2.Final. In the case of a default installation without a security realm reference, an attacker can successfully access the server without authentication. NOTE: the Security Realms documentation in the product's Admin Guide indicates that "without a security realm reference" implies "effectively unsecured." The vendor explicitly supports these unsecured configurations because they have valid use cases during development.
Affected Software
Event History
Frequently Asked Questions
What is the vulnerability ID of this issue?
The vulnerability ID of this issue is CVE-2018-10683.
What is the severity of CVE-2018-10683?
The severity of CVE-2018-10683 is critical with a CVSS score of 9.8.
What is the affected software?
The affected software is WildFly 10.1.2.Final.
How can an attacker exploit this vulnerability?
An attacker can successfully access the server without authentication in a default installation without a security realm reference.
Is there a fix available for CVE-2018-10683?
There is no information provided about a fix for CVE-2018-10683. It is advised to refer to the vendor's security advisory or contact the vendor for mitigation steps.