PT-2018-5029 · Red Hat · Bpm Suite 6+1
Pavel Polischouk
·
Published
2018-08-01
·
Updated
2023-02-12
·
CVE-2016-8608
CVSS v3.1
5.4
Medium
| Vector | AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N |
Name of the Vulnerable Software and Affected Versions
JBoss BRMS 6 and BPM Suite 6
Description
The issue is related to a stored XSS flaw in the business process editor, caused by an incomplete fix. Remote, authenticated attackers with privileges to create business processes can store scripts that are not properly sanitized, allowing them to be executed when shown to other users, including administrators.
Recommendations
For JBoss BRMS 6 and BPM Suite 6, consider restricting access to the business process editor to minimize the risk of exploitation until a proper fix is applied. As a temporary workaround, ensure that all scripts created within business processes are manually sanitized before being displayed to other users.
Fix
XSS
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Bpm Suite 6
Jboss Brms 6