EAP: cache is shared between all applications in a security domain
Published Jan 2, 2020
6.5
MEDIUMCVSS 3.1
EPSS 0.78%
Description
In JBoss EAP 6 a security domain is configured to use a cache that is shared between all applications that are in the security domain. This could allow an authenticated user in one application to access protected resources in another application without proper authorization. Although this is an intended functionality, it was not clearly documented which can mislead users into thinking that a security domain cache is isolated to a single application.
Affected products
-
- Version 6StatusaffectedConstraints-
- Version
- 6.0.0
No data.
Red Hat JBoss Enterprise Application Platform 6
doc-Security_Guide
Affected
| Product | Package | State | Advisory |
|---|---|---|---|
| Red Hat JBoss Enterprise Application Platform 6 | doc-Security_Guide | Affected | n/a |
No package ranges for this CVE.
Remediation
Red Hat statement
The fix for this flaw has been determined to be an addition to documentation. An admonition has been added to the relevant documentation that explain security domain usage in Red Hat JBoss Enterprise Application Platform 6. No security advisory will be published for this fix.
Metrics
No CVSS v4.0 score for this CVE.
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
No CVSS v3.0 score for this CVE.
AV:N/AC:L/Au:S/C:P/I:N/A:N
This CVE is not in the KEV list.
No CISA SSVC assessment for this CVE yet.
Estimated probability of exploitation in the wild in the next 30 days (FIRST EPSS). As of Oct 1, 2026.
Score over time
2022–2026- EPSS v2
- EPSS v3
- EPSS v4
- EPSS v5
Percentile over time
- EPSS v2
- EPSS v3
- EPSS v4
- EPSS v5
Table of values (10 key points)
Flat stretches are collapsed; showing up to 120 newest points.
| Date | Score | Percentile | Model |
|---|---|---|---|
| Oct 1, 2026 | 0.78% (0.00776) | 54.17th | v5 (v2026.06.15) |
| Jun 15, 2026 | 0.78% (0.00776) | 50.84th | v5 (v2026.06.15) |
| Mar 17, 2025 | 0.18% (0.00180) | 37.27th | v4 (v2025.03.14) |
| Dec 12, 2024 | 0.07% (0.00065) | 30.40th | v3 (v2023.03.01) |
| Jun 20, 2024 | 0.07% (0.00065) | 28.44th | v3 (v2023.03.01) |
| Mar 7, 2023 | 0.07% (0.00065) | 26.41th | v3 (v2023.03.01) |
| Mar 6, 2023 | 0.89% (0.00885) | 27.89th | v2 (v2022.01.01) |
| Sep 10, 2022 | 0.89% (0.00885) | 26.24th | v2 (v2022.01.01) |
| Apr 1, 2022 | 0.89% (0.00885) | 24.24th | v2 (v2022.01.01) |
| Feb 4, 2022 | 0.89% (0.00885) | 10.50th | v2 (v2022.01.01) |
References (6)
- https://access.redhat.com/security/cve/CVE-2014-0169 Vendor Advisory
- https://access.redhat.com/security/cve/cve-2014-0169 x_refsource_MISCVendor Advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=1084841 Issue Tracking
- https://bugzilla.redhat.com/show_bug.cgi?id=CVE-2014-0169 x_refsource_MISCIssue TrackingVendor Advisory
- https://nvd.nist.gov/vuln/detail/CVE-2014-0169
- https://www.cve.org/CVERecord?id=CVE-2014-0169
| Link | Providers | Tags |
|---|---|---|
| https://access.redhat.com/security/cve/CVE-2014-0169 | Vendor Advisory | |
| https://access.redhat.com/security/cve/cve-2014-0169 | x_refsource_MISCVendor Advisory | |
| https://bugzilla.redhat.com/show_bug.cgi?id=1084841 | Issue Tracking | |
| https://bugzilla.redhat.com/show_bug.cgi?id=CVE-2014-0169 | x_refsource_MISCIssue TrackingVendor Advisory | |
| https://nvd.nist.gov/vuln/detail/CVE-2014-0169 | ||
| https://www.cve.org/CVERecord?id=CVE-2014-0169 |
Change history (0)
No recorded changes yet.