Downgrade Attack Vulnerability in Wildfly by Red Hat
CVE-2019-14887
7.4HIGH
What is CVE-2019-14887?
A vulnerability exists in Wildfly where the 'enabled-protocols' setting is ignored when an OpenSSL security provider is in use. This flaw allows an attacker to target and manipulate the traffic from Wildfly, leading to a possibility of downgrading the connection to a less secure TLS version. Consequently, the encryption may be compromised, exposing sensitive data traversing the network. The versions impacted by this vulnerability include Wildfly 7.2.0.GA, 7.2.3.GA, and 7.2.5.CR2, necessitating immediate remediation to safeguard against potential data leaks.
Affected Version(s)
wildfly 7.2.0.GA, 7.2.3.GA, 7.2.5.CR2