It was reported that Direct Web Remoting (DWR) is vulnerable to a cross-site scripting flaw. DWR is used in Red Hat Satellite Server 5.6; however, it is not yet clear whether the affected functionality is exposed in that product or not. Reference: http://jvn.jp/en/jp/JVN52422792/