CVE-2014-0169
CVSS V2 Medium 4
CVSS V3 Medium 6.5
Description
In JBoss EAP 6 a security domain is configured to use a cache that is shared between all applications that are in the security domain. This could allow an authenticated user in one application to access protected resources in another application without proper authorization. Although this is an intended functionality, it was not clearly documented which can mislead users into thinking that a security domain cache is isolated to a single application.
Overview
- CVE ID
- CVE-2014-0169
- Assigner
- secalert@redhat.com
- Vulnerability Status
- Analyzed
- Published Version
- 2020-01-02T20:15:16
- Last Modified Date
- 2020-01-14T17:17:49
Weakness Enumerations
CPE Configuration (Product)
CPE | Vulnerable | Operator | Version Start | Version End |
---|---|---|---|---|
cpe:2.3:a:redhat:jboss_enterprise_application_platform:6.0.0:*:*:*:*:*:*:* | 1 | OR |
CVSS Version 2
- Version
- 2.0
- Vector String
- AV:N/AC:L/Au:S/C:P/I:N/A:N
- Access Vector
- NETWORK
- Access Compatibility
- LOW
- Authentication
- SINGLE
- Confidentiality Impact
- PARTIAL
- Integrity Impact
- NONE
- Availability Impact
- NONE
- Base Score
- 4
- Severity
- MEDIUM
- Exploitability Score
- 8
- Impact Score
- 2.9
CVSS Version 3
- Version
- 3.1
- Vector String
- CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
- Attack Vector
- NETWORK
- Attack Compatibility
- LOW
- Privileges Required
- LOW
- User Interaction
- NONE
- Scope
- UNCHANGED
- Confidentiality Impact
- HIGH
- Availability Impact
- NONE
- Base Score
- 6.5
- Base Severity
- MEDIUM
- Exploitability Score
- 2.8
- Impact Score
- 3.6
References
Reference URL | Reference Tags |
---|---|
https://access.redhat.com/security/cve/cve-2014-0169 | Vendor Advisory |
https://bugzilla.redhat.com/show_bug.cgi?id=CVE-2014-0169 | Issue Tracking Vendor Advisory |
Sources
Source Name | Source URL |
---|---|
NIST | https://nvd.nist.gov/vuln/detail/CVE-2014-0169 |
MITRE | https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2014-0169 |
History
Created | Old Value | New Value | Data Type | Notes |
---|---|---|---|---|
2022-05-10 16:53:45 | Added to TrackCVE | |||
2022-12-04 08:54:42 | 2020-01-02T20:15Z | 2020-01-02T20:15:16 | CVE Published Date | updated |
2022-12-04 08:54:42 | 2020-01-14T17:17:49 | CVE Modified Date | updated | |
2022-12-04 08:54:42 | Analyzed | Vulnerability Status | updated |