Wildfly

Vendor:

First CVE: May 9, 2018 · Active for 8 years

18
Total CVEs
More Total CVEs than 93% of tracked products
3.0
Avg CVEs / Year
Higher CVE frequency than 76% of tracked products
6.3
Avg CVSS
Higher Avg CVSS than 26% of tracked products
0.0%
KEV Rate
Bottom 1%

Trends Over Time

The number and severity of CVEs published that impact Wildfly over time

Volume of CVEsAvg CVSS Base Score
First CVE
May 9, 2018
8 years ago
Most Recent CVE
Jan 30, 2025
541 days ago

CVE Severity & Scoring

Wildfly18 CVEs
All CVEs352,427 CVEs
LowMediumHighCritical
Attack Vector
Local2 (11.1%)
Network16 (88.9%)
Unknown0 (0.0%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low12 (66.7%)
High6 (33.3%)
Unknown0 (0.0%)
User Interaction
None17 (94.4%)
Unknown0 (0.0%)
Required1 (5.6%)
Privileges Required
Low9 (50.0%)
High2 (11.1%)
None7 (38.9%)
Unknown0 (0.0%)

Top CVEs

Signals from CVEs in this product scope (18 CVEs).

18 CVEs · Highest risk first

CVEPublishedCVSSRiskKEVExploit
An issue was discovered in WildFly 10.1.2.Final. In the case of a default installation without a security realm reference, an attacker can successfully access the server without au
May 9, 20189.831NONO
A flaw was found when an OpenSSL security provider is used with Wildfly, the 'enabled-protocols' value in the Wildfly configuration isn't honored. An attacker could target the traf
Mar 16, 20209.128NONO
It was discovered that the ElytronManagedThread in Wildfly's Elytron subsystem in versions from 11 to 16 stores a SecurityIdentity to run the thread as. These threads do not necess
May 3, 20198.828NONO
A memory leak flaw was found in WildFly in all versions up to 21.0.0.Final, where host-controller tries to reconnect in a loop, generating new connections which are not properly cl
Nov 2, 20206.522NONO
A flaw was found in Wildfly affecting versions 19.0.0.Final, 19.1.0.Final, 20.0.0.Final, 20.0.1.Final, and 21.0.0.Final. When an application uses the OpenTracing API's java-interce
Dec 8, 20205.921NONO
The IIOP OpenJDK Subsystem in WildFly before version 14.0.0 does not honour configuration when SSL transport is required. Servers before this version that are configured with the f
Sep 4, 20185.921NONO
A flaw was found in the Wildfly Server Role Based Access Control (RBAC) provider. When authorization to control management operations is secured using the Role Based Access Control
Jan 30, 20256.520NONO
This is a concurrency issue that can result in the wrong caller principal being returned from the session context of an EJB that is configured with a RunAs principal. In particular
May 10, 20225.320NONO
A flaw was found in WildFly, where an attacker can see deployment names, endpoints, and any other data the trace payload may contain.
Sep 13, 20227.519NONO
A flaw was discovered in WildFly before 21.0.0.Final where, Resource adapter logs plain text JMS password at warning level on connection error, inserting sensitive information in t
Nov 24, 20205.319NONO

Exploit Exposure

Signals from CVEs in this product scope (18 CVEs).

CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
0 CVEs
0.0% of CVEs· Bottom 1%
Nuclei
0 CVEs
0.0% of CVEs· Bottom 1%
ExploitDB
0 CVEs
0.0% of CVEs· Bottom 1%

Social Chatter

Signals from CVEs in this product scope (18 CVEs).

Media Mentions

Signals from CVEs in this product scope (18 CVEs).

Top CNAs Publishing CVEs For Wildfly

Top CWEs

Versions

VersionCVE CountAvg CVSSAvg EPSSKEVExploits
7.2.519.11.1%00
7.2.319.11.1%00
7.2.019.11.1%00
28.0.016.50.7%00
27.0.015.30.8%00
21.0.015.91.1%00
20.0.115.91.1%00
20.0.015.91.1%00
19.1.015.91.1%00
19.0.015.91.1%00
17.0.013.30.8%00
16.0.013.30.8%00
10.1.219.81.8%00