PT-2020-7592 · Red Hat · Jboss Eap 6

Published

2020-01-02

·

Updated

2020-01-14

·

CVE-2014-0169

CVSS v2.0

4.0

Medium

VectorAV:N/AC:L/Au:S/C:P/I:N/A:N
Name of the Vulnerable Software and Affected Versions JBoss EAP 6 (affected versions not specified)
Description The issue concerns a security domain in JBoss EAP 6 that uses a shared cache among all applications within the domain. This could potentially allow an authenticated user in one application to access protected resources in another application without proper authorization. The functionality, although intended, was not clearly documented, which may mislead users into believing the cache is isolated to a single application.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Incorrect Authorization

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2014-0169

Affected Products

Jboss Eap 6