Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2014-0149

Опубликовано: 01 мая 2014
Источник: redhat
CVSS2: 4.3
EPSS Низкий

Описание

Multiple cross-site scripting (XSS) vulnerabilities in Red Hat JBoss Web Framework Kit 2.5.0 allow remote attackers to inject arbitrary web script or HTML via a (1) parameter or (2) id name.

Отчет

Red Hat JBoss Enterprise Application Platform 4 and 5; Red Hat JBoss Enterprise Portal Platform 5; and Red Hat JBoss Enterprise SOA Platform 4 and 5 are now in Phase 3, Extended Life Support, of their respective life cycles. This issue has been rated as having Moderate security impact and is not currently planned to be addressed in future updates. For additional information, refer to the Red Hat JBoss Middleware and Red Hat JBoss Operations Network Product Update and Support Policy: https://access.redhat.com/support/policy/updates/jboss_notes/

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat JBoss Enterprise Application Platform 4seam-remotingWill not fix
Red Hat JBoss Enterprise Application Platform 5seam-remotingWill not fix
Red Hat JBoss Portal 5seam-remotingWill not fix
Red Hat JBoss SOA Platform 4seam-remotingWill not fix
Red Hat JBoss SOA Platform 5seam-remotingWill not fix
Red Hat JBoss Web Framework Kit 2.5FixedRHSA-2014:046201.05.2014

Показывать по

Дополнительная информация

Статус:

Moderate
Дефект:
CWE-79

EPSS

Процентиль: 59%
0.00994
Низкий

4.3 Medium

CVSS2

Связанные уязвимости

nvd
больше 12 лет назад

Multiple cross-site scripting (XSS) vulnerabilities in Red Hat JBoss Web Framework Kit 2.5.0 allow remote attackers to inject arbitrary web script or HTML via a (1) parameter or (2) id name.

github
около 4 лет назад

Multiple cross-site scripting (XSS) vulnerabilities in Red Hat JBoss Web Framework Kit 2.5.0 allow remote attackers to inject arbitrary web script or HTML via a (1) parameter or (2) id name.

EPSS

Процентиль: 59%
0.00994
Низкий

4.3 Medium

CVSS2