Multiple cross-site scripting (XSS) flaws were found in JBoss Enterprise Portal Platform (EPP). If a remote attacker could trick a user, who was logged into EPP, into visiting a specially-crafted URL, it would lead to arbitrary web script execution in the context of the user's EPP session.
This issue has been addressed in following products: JBoss Enterprise Portal Platform 5.2.0 Via RHSA-2011:1822 https://rhn.redhat.com/errata/RHSA-2011-1822.html