A flaw was found in WildFly, where an attacker can see deployment names, endpoints, and any other data the trace payload may contain.
An improper initialization vulnerability was found in Galleon. When using Galleon to provision custom EAP or EAP-XP servers, the servers are created unsecured. This issue could allow an attacker to access remote HTTP services available from the server.