Caching Vulnerability in JBoss EAP 6 Impacting Security Domain Configurations
CVE-2014-0169
6.5MEDIUM
Summary
In JBoss EAP 6, a security domain is designed to use a shared cache among all applications within it. This configuration can inadvertently allow an authenticated user from one application to access protected resources in another application without the necessary authorization. While this behavior may be intentional, it lacks clear documentation, potentially leading to user misconceptions about the isolation of security domain caches across applications. Proper precautions and awareness are critical to mitigate this risk.
Affected Version(s)
JBoss EAP 6
References
CVSS V3.1
Score:
6.5
Severity:
MEDIUM
Confidentiality:
High
Integrity:
None
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged
Timeline
Vulnerability published
Vulnerability Reserved