CVE-2014-0169Incorrect Authorization in RED HAT Jboss EAP

Severity
6.5MEDIUMNVD
EPSS
0.2%
top 61.69%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedJan 2
Latest updateMay 17

Description

In JBoss EAP 6 a security domain is configured to use a cache that is shared between all applications that are in the security domain. This could allow an authenticated user in one application to access protected resources in another application without proper authorization. Although this is an intended functionality, it was not clearly documented which can mislead users into thinking that a security domain cache is isolated to a single application.

CVSS vector

CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:NExploitability: 2.8 | Impact: 3.6

Affected Packages2 packages

🔴Vulnerability Details

2
GHSA
GHSA-hwg9-xff6-g3rg: In JBoss EAP 6 a security domain is configured to use a cache that is shared between all applications that are in the security domain2022-05-17
CVEList
CVE-2014-0169: In JBoss EAP 6 a security domain is configured to use a cache that is shared between all applications that are in the security domain2020-01-02

📋Vendor Advisories

1
Red Hat
EAP: cache is shared between all applications in a security domain2014-04-08

💬Community

1
Bugzilla
CVE-2014-0169 JBoss EAP: cache is shared between all applications in a security domain2014-04-07
CVE-2014-0169 — Incorrect Authorization in RED | cvebase