PT-2018-5029 · Red Hat · Bpm Suite 6+1
Pavel Polischouk
·
Publicado
2018-08-01
·
Atualizado
2023-02-12
·
CVE-2016-8608
CVSS v3.1
5.4
Média
| Vetor | AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N |
Name of the Vulnerable Software and Affected Versions
JBoss BRMS 6 and BPM Suite 6
Description
The issue is related to a stored XSS flaw in the business process editor, caused by an incomplete fix. Remote, authenticated attackers with privileges to create business processes can store scripts that are not properly sanitized, allowing them to be executed when shown to other users, including administrators.
Recommendations
For JBoss BRMS 6 and BPM Suite 6, consider restricting access to the business process editor to minimize the risk of exploitation until a proper fix is applied. As a temporary workaround, ensure that all scripts created within business processes are manually sanitized before being displayed to other users.
Correção
XSS
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾
Enumeração de Fraquezas
Identificadores relacionados
Produtos afetados
Bpm Suite 6
Jboss Brms 6