VYPR
Vendor

Wildfly

Products
6
CVEs
22
Across products
23
Status
Private

Products

6

Recent CVEs

22
View all 22 CVEs →
  • CVE-2018-10683CriMay 9, 2018
    risk 0.64cvss 9.8epss 0.02

    An issue was discovered in WildFly 10.1.2.Final. In the case of a default installation without a security realm reference, an attacker can successfully access the server without authentication. NOTE: the Security Realms documentation in the product's Admin Guide indicates that…

  • CVE-2018-10682CriMay 9, 2018
    risk 0.64cvss 9.8epss 0.08

    An issue was discovered in WildFly 10.1.2.Final. It is possible for an attacker to access the administration panel on TCP port 9990 without any authentication using "anonymous" access that is automatically created. Once logged in, a misconfiguration present by default…

  • CVE-2019-14887CriMar 16, 2020
    risk 0.59cvss 9.1epss 0.01

    A flaw was found when an OpenSSL security provider is used with Wildfly, the 'enabled-protocols' value in the Wildfly configuration isn't honored. An attacker could target the traffic sent from Wildfly and downgrade the connection to a weaker version of TLS, potentially breaking…

  • CVE-2019-14843HigJan 7, 2020
    risk 0.57cvss 8.8epss 0.01

    A flaw was found in Wildfly Security Manager, running under JDK 11 or 8, that authorized requests for any requester. This flaw could be used by a malicious app deployed on the app server to access unauthorized information and possibly conduct further attacks. Versions shipped…

  • CVE-2019-3894HigMay 3, 2019
    risk 0.57cvss 8.8epss 0.02

    It was discovered that the ElytronManagedThread in Wildfly's Elytron subsystem in versions from 11 to 16 stores a SecurityIdentity to run the thread as. These threads do not necessarily terminate if the keep alive time has not expired. This could allow a shared thread to use the…

  • CVE-2021-3717HigMay 24, 2022
    risk 0.51cvss 7.8epss 0.00

    A flaw was found in Wildfly. An incorrect JBOSS_LOCAL_USER challenge location when using the elytron configuration may lead to JBOSS_LOCAL_USER access to all users on the machine. The highest threat from this vulnerability is to confidentiality, integrity, and availability. This…

  • CVE-2022-1278HigSep 13, 2022
    risk 0.49cvss 7.5epss 0.01

    A flaw was found in WildFly, where an attacker can see deployment names, endpoints, and any other data the trace payload may contain.

  • CVE-2020-10718HigSep 16, 2020
    risk 0.49cvss 7.5epss 0.01

    A flaw was found in Wildfly before wildfly-embedded-13.0.0.Final, where the embedded managed process API has an exposed setting of the Thread Context Classloader (TCCL). This setting is exposed as a public method, which can bypass the security manager. The highest threat from…

  • CVE-2025-23368HigMar 4, 2025
    risk 0.46cvss 8.1epss 0.01

    A flaw was found in Wildfly Elytron integration. The component does not implement sufficient measures to prevent multiple failed authentication attempts within a short time frame, making it more susceptible to brute force attacks via CLI.

  • CVE-2025-23367MedJan 30, 2025
    risk 0.42cvss 6.5epss 0.01

    A flaw was found in the Wildfly Server Role Based Access Control (RBAC) provider. When authorization to control management operations is secured using the Role Based Access Control provider, a user without the required privileges can suspend or resume the server. A user with a…

  • CVE-2024-10234MedOct 22, 2024
    risk 0.40cvss 6.1epss 0.01

    A vulnerability was found in Wildfly, where a user may perform Cross-site scripting in the Wildfly deployment system. This flaw allows an attacker or insider to execute a deployment with a malicious payload, which could trigger undesired behavior against the server.

  • CVE-2022-0866MedMay 10, 2022
    risk 0.35cvss 5.3epss 0.01

    This is a concurrency issue that can result in the wrong caller principal being returned from the session context of an EJB that is configured with a RunAs principal. In particular, the org.jboss.as.ejb3.component.EJBComponent class has an incomingRunAsIdentity field. This field…

  • CVE-2020-1719MedJun 7, 2021
    risk 0.35cvss 5.4epss 0.01

    A flaw was found in wildfly. The EJBContext principle is not popped back after invoking another EJB using a different Security Domain. The highest threat from this vulnerability is to data confidentiality and integrity. Versions before wildfly 20.0.0.Final are affected.

  • CVE-2020-25640MedNov 24, 2020
    risk 0.35cvss 5.3epss 0.01

    A flaw was discovered in WildFly before 21.0.0.Final where, Resource adapter logs plain text JMS password at warning level on connection error, inserting sensitive information in the log file.

  • CVE-2021-3536MedMay 20, 2021
    risk 0.31cvss 4.8epss 0.01

    A flaw was found in Wildfly in versions before 23.0.2.Final while creating a new role in domain mode via the admin console, it is possible to add a payload in the name field, leading to XSS. This affects Confidentiality and Integrity.

  • CVE-2020-27822MedDec 8, 2020
    risk 0.31cvss 5.9epss 0.01

    A flaw was found in Wildfly affecting versions 19.0.0.Final, 19.1.0.Final, 20.0.0.Final, 20.0.1.Final, and 21.0.0.Final. When an application uses the OpenTracing API's java-interceptors, there is a possibility of a memory leak. This flaw allows an attacker to impact the…

  • CVE-2019-3805MedMay 3, 2019
    risk 0.31cvss 4.7epss 0.00

    A flaw was discovered in wildfly versions up to 16.0.0.Final that would allow local users who are able to execute init.d script to terminate arbitrary processes on the system. An attacker could exploit this by modifying the PID file in /var/run/jboss-eap/ allowing the init.d…

  • CVE-2021-20250MedMay 13, 2021
    risk 0.28cvss 4.3epss 0.01

    A flaw was found in wildfly. The JBoss EJB client has publicly accessible privileged actions which may lead to information disclosure on the server it is deployed on. The highest threat from this vulnerability is to data confidentiality.

  • CVE-2018-14627MedSep 4, 2018
    risk 0.28cvss 5.3epss 0.01

    The IIOP OpenJDK Subsystem in WildFly before version 14.0.0 does not honour configuration when SSL transport is required. Servers before this version that are configured with the following setting allow clients to create plaintext connections: <transport-config…

  • CVE-2024-4029MedMay 2, 2024
    risk 0.27cvss 4.1epss 0.00

    A vulnerability was found in Wildfly’s management interface. Due to the lack of limitation of sockets for the management interface, it may be possible to cause a denial of service hitting the nofile limit as there is no possibility to configure or set a maximum number of…