LiveActive security incident?Get immediate response
CVE Record

CVE-2014-0169: In JBoss EAP 6 a security domain is configured to use a cache that is shared between all applications that...

In JBoss EAP 6 a security domain is configured to use a cache that is shared between all applications that are in the security domain. This could allow an authenticated user in one application to access protected resources in another application without proper authorization. Although this is an intended functionality, it was not clearly documented which can mislead users into thinking that a security domain cache is isolated to a single application.

UnknownCVSS not scoredNot KEV-listedUpdated
Glexia's TakeAutomated analysismoderate

Security readout for executives and security teams

Plain-English summary

This issue affects Red Hat JBoss EAP 6 configurations where multiple applications share one security domain cache. A user authenticated to one application might reach protected resources in another application without the expected authorization boundary. The source describes this as intended behavior that was not clearly documented, so risk depends heavily on local architecture.

Executive priority

Treat this as a configuration and architecture risk, not evidence of an active internet-wide emergency. Prioritize review if legacy JBoss EAP 6 hosts sensitive applications with shared login domains.

Technical view

JBoss EAP 6 security domains use a cache shared by all applications in that security domain. If teams assumed the cache was per-application, cross-application authorization expectations may be wrong. The bundle does not provide CVSS, CWE, affected minor versions, fixed versions, or concrete mitigation details.

Likely exposure

Exposure is most likely in JBoss EAP 6 environments hosting multiple applications under the same security domain, especially where those applications require separate authorization boundaries or tenant separation.

Exploitation context

The provided sources do not show active exploitation, public exploit availability, or KEV listing. Abuse requires an authenticated user in one application and a configuration where another application shares the same security domain cache.

Researcher notes

The key uncertainty is whether Red Hat issued specific patches or configuration recommendations outside the supplied bundle. The CVE text frames the behavior as intended but insufficiently documented, making exposure validation dependent on deployment topology and authorization assumptions.

Mitigation direction

  • Review Red Hat CVE and Bugzilla guidance for vendor-supported remediation.
  • Inventory JBoss EAP 6 deployments and shared security domain usage.
  • Separate applications that require distinct authorization boundaries.
  • Recheck authentication and authorization assumptions for shared security domains.
  • Document this behavior for operations and application teams.

Validation and detection

  • Confirm whether any JBoss EAP 6 instances remain in use.
  • Map applications assigned to each configured security domain.
  • Identify applications sharing domains despite requiring isolation.
  • Test cross-application access controls using non-privileged authenticated accounts.
  • Review access logs for unexpected cross-application resource access.
Prepared
Confidence
medium
Sources
4

Generated from the cited source records. This long-tail analysis has not been individually reviewed by a named human.

Potential ATT&CK relevance

Conservative CVE-to-ATT&CK context

These mappings and lookup hints may be relevant to the vulnerability behavior, CWE, affected product, or exposure path. Glexia-inferred context is not an official MITRE, ATT&CK, CWE, or CVE Program mapping.

ATT&CK lookup starting points

Use these exact CWE pages and searches to review the Glexia ATT&CK library from this CVE's weakness and description context.

cve · low confidence lookup

CVE-2014-0169 mapping review

Open the CVE-to-ATT&CK bridge for reviewed, inferred, or future official mappings tied to this CVE.

Open ATT&CK lookup
Vulnerability profileCVE Program record
Severity
Unknown
CVSS
Not scored
Known Exploited
No
Published
Official CVE source material

CNA and ADP enrichment extracted from CVE v5

These fields come from the CVE record and ADP containers, not from Glexia's Take. They preserve time-varying source decisions such as CISA SSVC, KEV status, CVSS metrics, and provider references.

0CVSS vectors
0Timeline events
0ADP providers
3Source links

CVSS and timeline data

No CVSS vectors or timeline events were available in the normalized CVE source material.

Source materials

Affected products

Products and packages named in the record

VendorProductVersion / packageStatus
Red HatJBoss EAP6Listed
Weakness

CWE details

No CWE listed

CWE links open Glexia weakness intelligence pages with official CWE context, developer remediation guidance, and related CVE mappings.