#VU16031 Security restrictions bypass in Red Hat Single Sign-On - CVE-2018-14627
Published: November 13, 2018 / Updated: November 23, 2018
Red Hat Single Sign-On
Red Hat Inc.
Description
The vulnerability allows a remote attacker to bypass security restrictions on the target system.
The vulnerability exists due to improper honour configuration when SSL transport is required. A remote unauthenticated attacker can bypass security restrictions to create plaintext connections: <transport-config confidentiality="required" trust-in-target="supported"/>