CVE-2019-3873

MEDIUM

JBoss Enterprise Application Platform 7.2 - Cross-Site Scripting via SAMLResponse xinclude Parameter

Title source: llm
STIX 2.1

Description

It was found that Picketlink as shipped with Jboss Enterprise Application Platform 7.2 would accept an xinclude parameter in SAMLresponse XML. An attacker could use this flaw to send a URL to achieve cross-site scripting or possibly conduct further attacks.

References (2)

Core 2
Core References
Issue Tracking, Vendor Advisory x_refsource_confirm
https://bugzilla.redhat.com/show_bug.cgi?id=CVE-2019-3873
Third Party Advisory, VDB Entry vdb-entry x_refsource_bid
http://www.securityfocus.com/bid/108739

Scores

CVSS v3 6.4
EPSS 0.0040
EPSS Percentile 61.1%
Attack Vector NETWORK
CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:C/C:N/I:L/A:L

Details

CWE
CWE-79
Status published
Products (2)
redhat/jboss_enterprise_application_platform 7.2.0
redhat/single_sign-on 7.0
Published Jun 12, 2019
Tracked Since Feb 18, 2026