Caching Vulnerability in JBoss EAP 6 Impacting Security Domain Configurations
CVE-2014-0169
6.5MEDIUM
Key Information:
What is CVE-2014-0169?
In JBoss EAP 6, a security domain is designed to use a shared cache among all applications within it. This configuration can inadvertently allow an authenticated user from one application to access protected resources in another application without the necessary authorization. While this behavior may be intentional, it lacks clear documentation, potentially leading to user misconceptions about the isolation of security domain caches across applications. Proper precautions and awareness are critical to mitigate this risk.
Affected Version(s)
JBoss EAP 6