Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2016-6343

Опубликовано: 16 мар. 2017
Источник: redhat
CVSS3: 6.1
CVSS2: 5.8
EPSS Низкий

Описание

JBoss BPM Suite 6 is vulnerable to a reflected XSS via dashbuilder. Remote attackers can entice authenticated users that have privileges to access dashbuilder (usually admins) to click on links to /dashbuilder/Controller containing malicious scripts. Successful exploitation would allow execution of script code within the context of the affected user.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat BPM Suite 6dashbuilderAffected
Red Hat JBoss BRMS 6dashbuilderNot affected
Red Hat JBoss BPMS 6.4FixedRHSA-2017:055716.03.2017
Red Hat JBoss Data Virtualization 6.4dashbuilderFixedRHSA-2018:029613.02.2018

Показывать по

Дополнительная информация

Статус:

Moderate
Дефект:
CWE-79

EPSS

Процентиль: 58%
0.00365
Низкий

6.1 Medium

CVSS3

5.8 Medium

CVSS2

Связанные уязвимости

CVSS3: 6.1
nvd
больше 7 лет назад

JBoss BPM Suite 6 is vulnerable to a reflected XSS via dashbuilder. Remote attackers can entice authenticated users that have privileges to access dashbuilder (usually admins) to click on links to /dashbuilder/Controller containing malicious scripts. Successful exploitation would allow execution of script code within the context of the affected user.

CVSS3: 5.4
github
больше 3 лет назад

JBoss BPM Suite 6 is vulnerable to a reflected XSS via dashbuilder. Remote attackers can entice authenticated users that have privileges to access dashbuilder (usually admins) to click on links to /dashbuilder/Controller containing malicious scripts. Successful exploitation would allow execution of script code within the context of the affected user.

EPSS

Процентиль: 58%
0.00365
Низкий

6.1 Medium

CVSS3

5.8 Medium

CVSS2