Red Hat Bugzilla – Bug 1358523
CVE-2016-5398 stored XSS in JBoss BPM suite business process editor
Last modified: 2016-10-18 15:53:07 EDT
JBoss BPM Suite 6.3.0 is vulnerable to a stored XSS via business process editor. Remote authenticated attackers that have privileges to create business processes can store scripts in them, which are not properly sanitized before showing to other users, including admins.
Acknowledgments: Name: Jeremy Choi (Red Hat Product Security Team)
This issue has been addressed in the following products: Red Hat JBoss BPM Suite 6.3.3 Via RHSA-2016:1969 https://rhn.redhat.com/errata/RHSA-2016-1969.html
This issue has been addressed in the following products: Red Hat JBoss BRMS 6.3.3 Via RHSA-2016:1968 https://rhn.redhat.com/errata/RHSA-2016-1968.html