Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2016-5398

Опубликовано: 28 сент. 2016
Источник: redhat
CVSS3: 5.4
CVSS2: 5.5
EPSS Низкий

Описание

Cross-site scripting (XSS) vulnerability in Business Process Editor in Red Hat JBoss BPM Suite before 6.3.3 allows remote authenticated users to inject arbitrary web script or HTML by levering permission to create business processes.

A security flaw was found in the way Business Process Editor displays the business process details to the user. A remote authenticated attacker with privilege to create business processes could use this flaw to conduct stored XSS attacks against other users.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat BPM Suite 6business-centralAffected
Red Hat JBoss BRMS 6business-centralAffected
Red Hat JBoss BPMS 6.3FixedRHSA-2016:196928.09.2016
Red Hat JBoss BRMS 6.3FixedRHSA-2016:196828.09.2016

Показывать по

Дополнительная информация

Статус:

Moderate
Дефект:
CWE-79
https://bugzilla.redhat.com/show_bug.cgi?id=1358523stored XSS in JBoss BPM suite business process editor

EPSS

Процентиль: 41%
0.00191
Низкий

5.4 Medium

CVSS3

5.5 Medium

CVSS2

Связанные уязвимости

CVSS3: 5.4
nvd
больше 9 лет назад

Cross-site scripting (XSS) vulnerability in Business Process Editor in Red Hat JBoss BPM Suite before 6.3.3 allows remote authenticated users to inject arbitrary web script or HTML by levering permission to create business processes.

CVSS3: 5.4
github
больше 3 лет назад

Cross-site scripting (XSS) vulnerability in Business Process Editor in Red Hat JBoss BPM Suite before 6.3.3 allows remote authenticated users to inject arbitrary web script or HTML by levering permission to create business processes.

EPSS

Процентиль: 41%
0.00191
Низкий

5.4 Medium

CVSS3

5.5 Medium

CVSS2