wildfly: Anonymous access via 9990 port allows RCE via war file upload
Published May 9, 2018
9.8
CRITICALCVSS 3.1
EPSS 8.25%
Description
An issue was discovered in WildFly 10.1.2.Final. It is possible for an attacker to access the administration panel on TCP port 9990 without any authentication using "anonymous" access that is automatically created. Once logged in, a misconfiguration present by default (auto-deployment) permits an anonymous user to deploy a malicious .war file, leading to remote code execution. NOTE: the vendor indicates that anonymous access is not available in the default installation; however, it remains optional because there are several use cases for it, including development environments and network architectures that have a proxy server for access control to the WildFly server
Affected products
No data.
-
- Version 10.1.2StatusaffectedConstraints-
- Version
Red Hat JBoss Data Grid 7
wildfly
Not affected
Red Hat JBoss Enterprise Application Platform 7
wildfly
Not affected
Red Hat Single Sign-On 7
wildfly
Not affected
Red Hat Virtualization 4
eap7-wildfly
Not affected
| Product | Package | State | Advisory |
|---|---|---|---|
| Red Hat JBoss Data Grid 7 | wildfly | Not affected | n/a |
| Red Hat JBoss Enterprise Application Platform 7 | wildfly | Not affected | n/a |
| Red Hat Single Sign-On 7 | wildfly | Not affected | n/a |
| Red Hat Virtualization 4 | eap7-wildfly | Not affected | n/a |
No package ranges for this CVE.
Remediation
Red Hat statement
Red Hat Product Security does not consider this issue as a vulnerability. The default installation are by default secured which means that management interfaces are set to have an authentication mechanism. Even without security on the management interfaces there are other approaches that could be taken, as an example a proxy fronting the server could be taking over the configuration. A second one could be the application server is running on an isolated device that does not allow network connections to it so only a local trusted process can communicate with it. Our default out of the box security considers that the server could be installed on a multi-user server so other users could inadvertently gain access if we had no security. However in many cases the server will be installed on a single user workstation for developer use, in that case being able to switch off security is desirable so the admin console can be accessed without the need for user accounts. As we switch to the Elytron configuration it is also possible for an administrator to define anonymous authentication policies even if sasl-authentication-factory is not referenced. HTTP remains the same, it is either on or off, a user could however still implement a custom anonymous mechanism.
Metrics
No CVSS v4.0 score for this CVE.
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
1 other source (Red Hat) ▾
CVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H
AV:N/AC:L/Au:N/C:C/I:C/A:C
This CVE is not in the KEV list.
CISA SSVC (Vulnrichment)
Stakeholder-Specific Vulnerability Categorization from CISA ADP.
Exploitation
PoCAutomatable
YesTechnical Impact
TotalDecision
n/aAssessed Jul 23, 2024 · SSVC 2.0.3
Estimated probability of exploitation in the wild in the next 30 days (FIRST EPSS). As of Oct 2, 2026.
Score over time
2021–2026- EPSS v1
- EPSS v2
- EPSS v3
- EPSS v4
- EPSS v5
Percentile over time
- EPSS v1
- EPSS v2
- EPSS v3
- EPSS v4
- EPSS v5
Table of values (21 key points)
Flat stretches are collapsed; showing up to 120 newest points.
| Date | Score | Percentile | Model |
|---|---|---|---|
| Oct 2, 2026 | 8.25% (0.08255) | 94.74th | v5 (v2026.06.15) |
| Jun 15, 2026 | 8.16% (0.08159) | 94.11th | v5 (v2026.06.15) |
| Mar 7, 2026 | 7.43% (0.07430) | 91.61th | v4 (v2025.03.14) |
| Aug 31, 2025 | 10.04% (0.10045) | 92.78th | v4 (v2025.03.14) |
| Mar 30, 2025 | 8.37% (0.08368) | 91.47th | v4 (v2025.03.14) |
| Mar 29, 2025 | 19.60% (0.19595) | 92.52th | v4 (v2025.03.14) |
| Mar 17, 2025 | 8.58% (0.08585) | 91.77th | v4 (v2025.03.14) |
| Dec 17, 2024 | 2.51% (0.02514) | 89.82th | v3 (v2023.03.01) |
| May 24, 2024 | 1.39% (0.01394) | 86.37th | v3 (v2023.03.01) |
| Apr 18, 2024 | 1.23% (0.01231) | 85.24th | v3 (v2023.03.01) |
| Mar 18, 2024 | 1.74% (0.01736) | 87.59th | v3 (v2023.03.01) |
| Mar 7, 2023 | 1.69% (0.01690) | 85.74th | v3 (v2023.03.01) |
| Mar 6, 2023 | 1.27% (0.01267) | 67.52th | v2 (v2022.01.01) |
| Feb 3, 2023 | 1.27% (0.01267) | 66.74th | v2 (v2022.01.01) |
| Oct 18, 2022 | 1.16% (0.01156) | 60.36th | v2 (v2022.01.01) |
| Apr 1, 2022 | 1.16% (0.01156) | 58.36th | v2 (v2022.01.01) |
| Feb 4, 2022 | 1.16% (0.01156) | 34.92th | v2 (v2022.01.01) |
| Feb 3, 2022 | 0.92% (0.00918) | 25.93th | v1 |
| Jan 6, 2022 | 0.92% (0.00918) | 25.29th | v1 |
| Sep 1, 2021 | 0.92% (0.00918) | 60.61th | v1 |
| Apr 14, 2021 | 0.92% (0.00918) | 0.00th | v1 |
References (5)
- https://access.redhat.com/security/cve/CVE-2018-10682 Vendor Advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=1534476 Issue Tracking
- https://github.com/kmkz/exploit/blob/master/CVE-2018-10682-CVE-2018-10683.txt x_refsource_MISCExploitThird Party Advisory
- https://nvd.nist.gov/vuln/detail/CVE-2018-10682
- https://www.cve.org/CVERecord?id=CVE-2018-10682
| Link | Providers | Tags |
|---|---|---|
| https://access.redhat.com/security/cve/CVE-2018-10682 | Vendor Advisory | |
| https://bugzilla.redhat.com/show_bug.cgi?id=1534476 | Issue Tracking | |
| https://github.com/kmkz/exploit/blob/master/CVE-2018-10682-CVE-2018-10683.txt | x_refsource_MISCExploitThird Party Advisory | |
| https://nvd.nist.gov/vuln/detail/CVE-2018-10682 | ||
| https://www.cve.org/CVERecord?id=CVE-2018-10682 |
Change history (0)
No recorded changes yet.