Aller au contenu principal
CRITICAL

CVE-2018-10682

CVSS v3

9.8

CRITICAL

Score EPSS

9.6 %

probabilité d’exploitation

CISA KEV

Non

exploitation connue

Exploitation

statut SSVC

Description

An issue was discovered in WildFly 10.1.2.Final. It is possible for an attacker to access the administration panel on TCP port 9990 without any authentication using "anonymous" access that is automatically created. Once logged in, a misconfiguration present by default (auto-deployment) permits an anonymous user to deploy a malicious .war file, leading to remote code execution. NOTE: the vendor indicates that anonymous access is not available in the default installation; however, it remains optional because there are several use cases for it, including development environments and network architectures that have a proxy server for access control to the WildFly server

Détails techniques

Publiée le
2018-05-09

Questions fréquentes

Qu’est-ce que CVE-2018-10682 ?

An issue was discovered in WildFly 10.1.2.Final. It is possible for an attacker to access the administration panel on TCP port 9990 without any authentication using "anonymous" access that is automatically created. Once logged in, a misconfiguration present by default (auto-deployment) permits an anonymous user to deploy a malicious .war file, leading to remote code execution. NOTE: the vendor indicates that anonymous access is not available in the default installation; however, it remains optional because there are several use cases for it, including development environments and network architectures that have a proxy server for access control to the WildFly server

CVE-2018-10682 est-elle activement exploitée ?

Aucune exploitation active de CVE-2018-10682 n’est confirmée. Le score EPSS est de 9.6 %, soit la probabilité estimée d’exploitation dans les 30 prochains jours.

Quel est le score CVSS de CVE-2018-10682 ?

CVE-2018-10682 a un score de base CVSS v3 de 9.8 (gravité CRITICAL).

CVE-2018-10682 touche-t-elle votre environnement ?

Utilisez isMalicious pour vérifier si l’une de vos IP ou l’un de vos domaines est associé aux IOC de cette vulnérabilité.

Sans carte bancaire · 500 vérifications gratuites par mois · Clé API gratuite