Multiple reflected cross-site scripting (XSS) flaws were found in GateIn Portal. If a remote attacker could trick a user, who was logged into the GateIn Portal interface, into visiting a specially-crafted URL, it would lead to arbitrary web script execution in the context of the user's GateIn Portal session.
Acknowledgements: Red Hat would like to thank Hideharu Ohkuma of Ricoh Company for reporting these issues.
This issue has been addressed in following products: JBoss Enterprise Portal Platform 5.2.2 Via RHSA-2013:0141 https://rhn.redhat.com/errata/RHSA-2013-0141.html