JBoss BRMS 6 and BPM Suite 6 before 6.4.3 are vulnerable to a reflected XSS via artifact upload. A malformed XML file, if uploaded, causes an error message to appear that includes part of the bad XML code verbatim without filtering out scripts. Successful exploitation would allow execution of script code within the context of the affected user.
References
Link Resource
http://www.securityfocus.com/bid/98385 Third Party Advisory VDB Entry
https://access.redhat.com/errata/RHSA-2017:1217 Broken Link Vendor Advisory
https://access.redhat.com/errata/RHSA-2017:1218 Broken Link Vendor Advisory
https://bugzilla.redhat.com/show_bug.cgi?id=CVE-2017-7463 Issue Tracking Vendor Advisory
History

No history.

cve-icon MITRE Information

Status: PUBLISHED

Assigner: redhat

Published: 2018-07-27T18:00:00

Updated: 2018-07-28T09:57:01

Reserved: 2017-04-05T00:00:00


Link: CVE-2017-7463

JSON object: View

cve-icon NVD Information

Status : Modified

Published: 2018-07-27T18:29:01.280

Modified: 2019-10-09T23:29:36.170


Link: CVE-2017-7463

JSON object: View

cve-icon Redhat Information

No data.

CWE