CVE-2016-6343

MEDIUM

JBoss BPM Suite 6.0.0-6.4.1 - Reflected Cross-Site Scripting via Dashbuilder Controller

Title source: llm
STIX 2.1

Description

JBoss BPM Suite 6 is vulnerable to a reflected XSS via dashbuilder. Remote attackers can entice authenticated users that have privileges to access dashbuilder (usually admins) to click on links to /dashbuilder/Controller containing malicious scripts. Successful exploitation would allow execution of script code within the context of the affected user.

References (4)

Core 4
Core References
Third Party Advisory, VDB Entry vdb-entry x_refsource_bid
http://www.securityfocus.com/bid/96987
Broken Link, Vendor Advisory vendor-advisory x_refsource_redhat
http://rhn.redhat.com/errata/RHSA-2017-0557.html
Vendor Advisory vendor-advisory x_refsource_redhat
https://access.redhat.com/errata/RHSA-2018:0296

Scores

CVSS v3 6.1
EPSS 0.0166
EPSS Percentile 74.1%
Attack Vector NETWORK
CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N

Details

CWE
CWE-79
Status published
Products (1)
redhat/jboss_bpm_suite 6.0.0 - 6.4.2
Published Oct 31, 2018
Tracked Since Feb 18, 2026