JBoss BPM Suite 6.3.0 is vulnerable to a stored XSS via business process editor. Remote authenticated attackers that have privileges to create business processes can store scripts in them, which are not properly sanitized before showing to other users, including admins.
Acknowledgments: Name: Jeremy Choi (Red Hat Product Security Team)
This issue has been addressed in the following products: Red Hat JBoss BPM Suite 6.3.3 Via RHSA-2016:1969 https://rhn.redhat.com/errata/RHSA-2016-1969.html
This issue has been addressed in the following products: Red Hat JBoss BRMS 6.3.3 Via RHSA-2016:1968 https://rhn.redhat.com/errata/RHSA-2016-1968.html