Jboss EAP Inadequate Encryption Strength Vulnerability - CVE-2019-14887 - Vulnerability Database

Jboss EAP Inadequate Encryption Strength Vulnerability - CVE-2019-14887

Critical
Reference: CVE-2019-14887
Title: Jboss EAP Inadequate Encryption Strength Vulnerability
Overview:

A flaw was found when an OpenSSL security provider is used with Wildfly the 39enabled-protocols39 value in the Wildfly configuration isn39t honored. An attacker could target the traffic sent from Wildfly and downgrade the connection to a weaker version of TLS potentially breaking the encryption. This could lead to a leak of the data being passed over the network. Wildfly version 7.2.0.GA 7.2.3.GA and 7.2.5.CR2 are believed to be vulnerable.