CVE-2011-4575: Input Validation
Cross-site scripting (XSS) vulnerability in the JMX console in JBoss Enterprise Application Platform (EAP) before 5.2.0, Web Platform (EWP) before 5.2.0, BRMS Platform before 5.3.1, and SOA Platform before 5.3.1 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.
Other sources
The parameters passed to operation invocations on the JMX console are not properly sanitized. Remote attackers can use this flaw to inject arbitrary web script or HTML into the JMX console.
— Red Hat
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2011-4575?
CVE-2011-4575 has been classified as a medium severity vulnerability due to its potential for cross-site scripting attacks.
How do I fix CVE-2011-4575?
To fix CVE-2011-4575, upgrade to JBoss Enterprise Application Platform 5.2.0 or later, Web Platform 5.2.0 or later, or BRMS and SOA Platforms 5.3.1 or later.
What versions are affected by CVE-2011-4575?
CVE-2011-4575 affects JBoss Enterprise Application Platform versions before 5.2.0, Web Platform versions before 5.2.0, and BRMS and SOA Platforms before 5.3.1.
What types of attacks can be executed due to CVE-2011-4575?
CVE-2011-4575 allows remote attackers to inject arbitrary web scripts or HTML into the JMX console, enabling potential cross-site scripting attacks.
Is CVE-2011-4575 present in JBoss EAP 5.2.0?
No, CVE-2011-4575 is not present in JBoss EAP version 5.2.0 and later, as it has been patched.