Vulnerability Name: | CVE-2014-0169 (CCN-174751) | ||||||||||||
Assigned: | 2013-12-03 | ||||||||||||
Published: | 2014-04-07 | ||||||||||||
Updated: | 2020-01-14 | ||||||||||||
Summary: | In JBoss EAP 6 a security domain is configured to use a cache that is shared between all applications that are in the security domain. This could allow an authenticated user in one application to access protected resources in another application without proper authorization. Although this is an intended functionality, it was not clearly documented which can mislead users into thinking that a security domain cache is isolated to a single application. | ||||||||||||
CVSS v3 Severity: | 6.5 Medium (CVSS v3.1 Vector: CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N) 5.7 Medium (Temporal CVSS v3.1 Vector: CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N/E:U/RL:U/RC:R)
6.3 Medium (CCN Temporal CVSS v3.1 Vector: CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:L/A:N/E:U/RL:U/RC:R)
| ||||||||||||
CVSS v2 Severity: | 4.0 Medium (CVSS v2 Vector: AV:N/AC:L/Au:S/C:P/I:N/A:N)
| ||||||||||||
Vulnerability Type: | CWE-863 | ||||||||||||
Vulnerability Consequences: | Bypass Security | ||||||||||||
References: | Source: MITRE Type: CNA CVE-2014-0169 Source: MISC Type: Vendor Advisory https://access.redhat.com/security/cve/cve-2014-0169 Source: CCN Type: Red Hat Bugzilla Bug 1084841 (CVE-2014-0169) - CVE-2014-0169 JBoss EAP: cache is shared between all applications in a security domain Source: MISC Type: Issue Tracking, Vendor Advisory https://bugzilla.redhat.com/show_bug.cgi?id=CVE-2014-0169 Source: CCN Type: Red Hat Web site Red Hat JBoss Enterprise Application Platform Source: XF Type: UNKNOWN redhat-cve20140169-sec-bypass(174751) | ||||||||||||
Vulnerable Configuration: | Configuration 1: Configuration CCN 1: ![]() | ||||||||||||
BACK |