Hide Forgot
A cross-site scripting (XSS) vulnerability was found in the JBoss Management Console. Users with roles that can create objects in the application can exploit this to attack other privileged users.
Acknowledgments: Name: Jakub Palaczynski
This issue has been addressed in the following products: Red Hat JBoss Enterprise Application Platform Via RHSA-2019:0362 https://access.redhat.com/errata/RHSA-2019:0362
This issue has been addressed in the following products: Red Hat JBoss Enterprise Application Platform 7.1 for RHEL 6 Via RHSA-2019:0364 https://access.redhat.com/errata/RHSA-2019:0364
This issue has been addressed in the following products: Red Hat JBoss Enterprise Application Platform 7.1 for RHEL 7 Via RHSA-2019:0365 https://access.redhat.com/errata/RHSA-2019:0365
This issue has been addressed in the following products: Red Hat Single Sign-On 7.2.6 zip Via RHSA-2019:0380 https://access.redhat.com/errata/RHSA-2019:0380
This issue has been addressed in the following products: Red Hat JBoss Enterprise Application Platform 6.4 for RHEL 5 Via RHSA-2019:1159 https://access.redhat.com/errata/RHSA-2019:1159
This issue has been addressed in the following products: Red Hat JBoss Enterprise Application Platform 6.4 for RHEL 7 Via RHSA-2019:1161 https://access.redhat.com/errata/RHSA-2019:1161
This issue has been addressed in the following products: Red Hat JBoss Enterprise Application Platform 6.4 for RHEL 6 Via RHSA-2019:1160 https://access.redhat.com/errata/RHSA-2019:1160
This issue has been addressed in the following products: Red Hat JBoss Enterprise Application Platform Via RHSA-2019:1162 https://access.redhat.com/errata/RHSA-2019:1162
This vulnerability is out of security support scope for the following products: * Red Hat JBoss Operations Network 3 * Red Hat JBoss Fuse 6 * Red Hat JBoss Data Virtualization & Services 6 * Red Hat JBoss BRMS 6 * Red Hat JBoss BPM Suite 6 Please refer to https://access.redhat.com/support/policy/updates/jboss_notes for more details.