First published: Wed Jul 20 2016(Updated: )
Cross-site scripting (XSS) vulnerability in Business Process Editor in Red Hat JBoss BPM Suite before 6.3.3 allows remote authenticated users to inject arbitrary web script or HTML by levering permission to create business processes.
Credit: secalert@redhat.com
Affected Software | Affected Version | How to fix |
---|---|---|
redhat JBoss BPM suite | <=6.3.2 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2016-5398 is classified as a Medium severity vulnerability due to its potential impact on web application security.
To fix CVE-2016-5398, upgrade to Red Hat JBoss BPM Suite version 6.3.3 or later.
CVE-2016-5398 affects users of Red Hat JBoss BPM Suite versions up to 6.3.2.
CVE-2016-5398 is a Cross-site Scripting (XSS) vulnerability.
No, CVE-2016-5398 requires authenticated user access to leverage the vulnerability.