← Vulnerability feed

Vulnerability record · CVE-2022-1278 · published 13 September 2022

CVE-2022-1278: Redhat wildfly insecure default initialization vulnerability

Redhat · Wildfly

A flaw was found in WildFly, where an attacker can see deployment names, endpoints, and any other data the trace payload may contain.

7.5 CVSS 3.1 High EPSS 0.86% · top 43.1% CWE-1188 · Insecure default initialization
7.5CVSS 3.1 base score
0.86%EPSS exploitation probability, 30 days
NoNot in CISA KEV
8Affected product versions listed by NVD
2References
17 Jun 2026Last modified by NVD

Description

A flaw was found in WildFly, where an attacker can see deployment names, endpoints, and any other data the trace payload may contain.

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N

Affected products

8 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

LinkTags
https://bugzilla.redhat.com/show_bug.cgi?id=2073401 Issue TrackingVendor Advisory
https://bugzilla.redhat.com/show_bug.cgi?id=2073401 Issue TrackingVendor Advisory

Track CVE-2022-1278 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

7.5CVE-2023-44487HTTP/2 Rapid Reset stream cancellation denial of serviceThe HTTP/2 protocol permits a client to cancel many streams quickly, and the server's handling of those resets consumes disproportionate resources. T…KEVEPSS 100%analysed9.8CVE-2015-7501Red Hat JBoss Java deserialization allows remote command executionMultiple Red Hat JBoss products deserialize untrusted Java objects and, through the Apache Commons Collections library, allow remote attackers to exe…EPSS 86%analysed8.8CVE-2015-5182Redhat amq cross-site request forgery vulnerabilityCross-site request forgery (CSRF) vulnerability in the jolokia API in A-MQ.EPSS 0.63%8.1CVE-2023-4853Quarkus incorrect authorization vulnerabilityA flaw was found in Quarkus where HTTP security policies are not sanitizing certain character permutations correctly when accepting requests, resulti…EPSS 1.4%7.5CVE-2024-7885Redhat build of apache camel - hawtio race condition vulnerabilityA vulnerability was found in Undertow where the ProxyProtocolReadListener reuses the same StringBuilder instance across multiple requests. This issue…EPSS 2.6%7.5CVE-2022-4244Codehaus-plexus plexus-utils path traversal vulnerabilityA flaw was found in codeplex-codehaus. A directory traversal attack (also known as path traversal) aims to access files and directories stored outsid…EPSS 1.3%7.5CVE-2023-1108Redhat build of quarkus vulnerabilityA flaw was found in undertow. This issue makes achieving a denial of service possible due to an unexpected handshake status updated in SslConduit, wh…EPSS 1.8%7.5CVE-2022-4492Redhat build of quarkus server-side request forgery (ssrf) vulnerabilityThe undertow client is not checking the server identity presented by the server certificate in https connections. This is a compulsory step (at least…EPSS 0.60%

Source: NIST National Vulnerability Database (record CVE-2022-1278), CISA KEV, FIRST EPSS (scores of 2026-09-28). This page is refreshed as NVD updates the record.