Security Advisory

CVE-2016-8608

CVE vulnerability detail - eXtreme Datacenter Security Operations

Published 2018-08-01 14:00:00
Last updated 2024-08-06 02:27:40
Assigner redhat
CVSS score 5.4
State PUBLISHED

Description

JBoss BRMS 6 and BPM Suite 6 are vulnerable to a stored XSS via business process editor. The flaw is due to an incomplete fix for CVE-2016-5398. Remote, authenticated attackers that have privileges to create business processes can store scripts in them, which are not properly sanitized before showing to other users, including admins.