Multiple stored cross-site scripting (XSS) flaws were found in the Fuse Management Console. A remote attacker could use this flaw to perform an XSS attack against other users of the Fuse Management Console.
Upstream patch commits: https://github.com/jboss-fuse/fuse/commit/e280cb370323eeb759030919d5111ed809e8ded5 http://fusesource.com/forge/git/fuseenterprise.git/?p=fuseenterprise.git;a=commit;h=f5436ea1c5547c851bb6f92561272fe42c146e68
This issue has been addressed in following products: Red Hat JBoss Fuse 6.0.0 Red Hat JBoss A-MQ 6.0.0 Via RHSA-2013:1286 https://rhn.redhat.com/errata/RHSA-2013-1286.html
This issue has been addressed in following products: Fuse ESB Enterprise 7.1.0 Fuse MQ Enterprise 7.1.0 Fuse Management Console 7.1.0 Via RHSA-2013:1862 https://rhn.redhat.com/errata/RHSA-2013-1862.html