PT-2018-5029 · Red Hat · Bpm Suite 6+1

Pavel Polischouk

·

Publicado

2018-08-01

·

Atualizado

2023-02-12

·

CVE-2016-8608

CVSS v3.1

5.4

Média

VetorAV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N
Name of the Vulnerable Software and Affected Versions JBoss BRMS 6 and BPM Suite 6
Description The issue is related to a stored XSS flaw in the business process editor, caused by an incomplete fix. Remote, authenticated attackers with privileges to create business processes can store scripts that are not properly sanitized, allowing them to be executed when shown to other users, including administrators.
Recommendations For JBoss BRMS 6 and BPM Suite 6, consider restricting access to the business process editor to minimize the risk of exploitation until a proper fix is applied. As a temporary workaround, ensure that all scripts created within business processes are manually sanitized before being displayed to other users.

Correção

XSS

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

CVE-2016-8608

Produtos afetados

Bpm Suite 6
Jboss Brms 6