CVE-2014-0169
published 2020-01-02CVE-2014-0169: In JBoss EAP 6 a security domain is configured to use a cache that is shared between all applications that are in the security domain. This could allow an…
PriorityP433medium6.5CVSS 3.1
AVNACLPRLUINSUCHINAN
EPSS
0.78%
51.7th percentile
In JBoss EAP 6 a security domain is configured to use a cache that is shared between all applications that are in the security domain. This could allow an authenticated user in one application to access protected resources in another application without proper authorization. Although this is an intended functionality, it was not clearly documented which can mislead users into thinking that a security domain cache is isolated to a single application.
Affected
2 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| red_hat | jboss_eap | — | — |
| redhat | jboss_enterprise_application_platform | — | — |
CVSS provenance
nvdv3.16.5MEDIUMCVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
nvdv2.04.0MEDIUMAV:N/AC:L/Au:S/C:P/I:N/A:N
vendor_redhat6.5MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Red Hat
EAP: cache is shared between all applications in a security domain
vendor_redhat·2014-04-08·CVSS 6.5
CVE-2014-0169 [MEDIUM] EAP: cache is shared between all applications in a security domain
EAP: cache is shared between all applications in a security domain
In JBoss EAP 6 a security domain is configured to use a cache that is shared between all applications that are in the security domain. This could allow an authenticated user in one application to access protected resources in another application without proper authorization. Although this is an intended functionality, it was not clearly documented which can mislead users into thinking that a security domain cache is isolated to a single application.
Statement: The fix for this flaw has been determined to be an addition to documentation. An admonition has been added to the relevant documentation that explain security domain usage in Red Hat JBoss Enterprise Application Platform 6. No security advisory will be published for
GHSA
GHSA-hwg9-xff6-g3rg: In JBoss EAP 6 a security domain is configured to use a cache that is shared between all applications that are in the security domain
ghsa_unreviewed·2022-05-17
CVE-2014-0169 [MEDIUM] GHSA-hwg9-xff6-g3rg: In JBoss EAP 6 a security domain is configured to use a cache that is shared between all applications that are in the security domain
In JBoss EAP 6 a security domain is configured to use a cache that is shared between all applications that are in the security domain. This could allow an authenticated user in one application to access protected resources in another application without proper authorization. Although this is an intended functionality, it was not clearly documented which can mislead users into thinking that a security domain cache is isolated to a single application.
No detection rules found.
No public exploits indexed.
2020-01-02
Published