Vulnerabilities > CVE-2016-6343 - Unspecified vulnerability in Redhat Jboss BPM Suite

047910
CVSS 5.4 - MEDIUM
Attack vector
NETWORK
Attack complexity
LOW
Privileges required
LOW
Confidentiality impact
LOW
Integrity impact
LOW
Availability impact
NONE
network
low complexity
redhat

Summary

JBoss BPM Suite 6 is vulnerable to a reflected XSS via dashbuilder. Remote attackers can entice authenticated users that have privileges to access dashbuilder (usually admins) to click on links to /dashbuilder/Controller containing malicious scripts. Successful exploitation would allow execution of script code within the context of the affected user.

Redhat

advisories
  • rhsa
    idRHSA-2017:0557
  • rhsa
    idRHSA-2018:0296