Bug 1371801 (CVE-2016-6343) - CVE-2016-6343 Dashbuilder: Reflected XSS
Summary: CVE-2016-6343 Dashbuilder: Reflected XSS
Keywords:
Status: CLOSED ERRATA
Alias: CVE-2016-6343
Product: Security Response
Classification: Other
Component: vulnerability
Version: unspecified
Hardware: All
OS: Linux
medium
medium
Target Milestone: ---
Assignee: Red Hat Product Security
QA Contact:
URL:
Whiteboard:
Depends On: 1469738 1469739
Blocks: 1372094 1372135 1429673 1521173
TreeView+ depends on / blocked
 
Reported: 2016-08-31 07:10 UTC by Jeremy Choi
Modified: 2021-02-17 03:25 UTC (History)
15 users (show)

Fixed In Version:
Doc Type: Bug Fix
Doc Text:
JBoss BPM Suite 6 is vulnerable to a reflected XSS via dashbuilder. Remote attackers can entice authenticated users that have privileges to access dashbuilder (usually admins) to click on links to /dashbuilder/Controller containing malicious scripts. Successful exploitation would allow execution of script code within the context of the affected user.
Clone Of:
Environment:
Last Closed: 2018-08-07 15:16:48 UTC
Embargoed:


Attachments (Terms of Use)


Links
System ID Private Priority Status Summary Last Updated
Red Hat Product Errata RHSA-2017:0557 0 normal SHIPPED_LIVE Moderate: Red Hat JBoss BPM Suite security update 2017-03-17 01:09:43 UTC
Red Hat Product Errata RHSA-2018:0296 0 normal SHIPPED_LIVE Moderate: Red Hat JBoss Data Virtualization 6.4 security update 2018-02-13 20:48:28 UTC

Description Jeremy Choi 2016-08-31 07:10:59 UTC
JBoss BPM Suite 6 is vulnerable to a reflected XSS via dashbuilder. Remote attackers can entice authenticated users that have privileges to access dashbuilder (usually admins) to click on links to /dashbuilder/Controller containing malicious scripts. Successful exploitation would allow execution of script code within the context of the affected user.

Comment 1 Jeremy Choi 2016-08-31 07:11:09 UTC
Acknowledgments:

Name: Jeremy Choi (Red Hat Product Security Team)

Comment 3 David Gutierrez 2016-12-30 17:39:09 UTC
Hi @Jeremy, 

I'm not sure if I get what's the issue here. Can you please elaborate a bit more, and also give a detailed reproducer.

Thanks in advance.

Comment 5 errata-xmlrpc 2017-03-16 21:09:58 UTC
This issue has been addressed in the following products:

  Red Hat JBoss BPM Suite 6.4.2

Via RHSA-2017:0557 https://rhn.redhat.com/errata/RHSA-2017-0557.html

Comment 8 errata-xmlrpc 2018-02-13 15:48:40 UTC
This issue has been addressed in the following products:

  Red Hat JBoss Data Virtualization

Via RHSA-2018:0296 https://access.redhat.com/errata/RHSA-2018:0296


Note You need to log in before you can comment on or make changes to this bug.