Caching Vulnerability in JBoss EAP 6 Impacting Security Domain Configurations
CVE-2014-0169

6.5MEDIUM

Key Information:

Vendor
Red Hat
Status
Vendor
CVE Published:
2 January 2020

Summary

In JBoss EAP 6, a security domain is designed to use a shared cache among all applications within it. This configuration can inadvertently allow an authenticated user from one application to access protected resources in another application without the necessary authorization. While this behavior may be intentional, it lacks clear documentation, potentially leading to user misconceptions about the isolation of security domain caches across applications. Proper precautions and awareness are critical to mitigate this risk.

Affected Version(s)

JBoss EAP 6

References

CVSS V3.1

Score:
6.5
Severity:
MEDIUM
Confidentiality:
High
Integrity:
None
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.