First published: Tue Sep 06 2016(Updated: )
Multiple cross-site scripting (XSS) vulnerabilities in the admin pages in dashbuilder in Red Hat JBoss BPM Suite 6.3.2 allow remote attackers to inject arbitrary web script or HTML via unspecified vectors.
Credit: secalert@redhat.com
Affected Software | Affected Version | How to fix |
---|---|---|
redhat JBoss BPM suite | =6.3.2 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2016-7033 is categorized as a moderate severity vulnerability due to its potential for stored cross-site scripting attacks.
To fix CVE-2016-7033, upgrade to a patched version of the Red Hat JBoss BPM Suite beyond 6.3.2.
CVE-2016-7033 specifically affects Red Hat JBoss BPM Suite version 6.3.2.
CVE-2016-7033 contains multiple cross-site scripting (XSS) vulnerabilities allowing injection of arbitrary web scripts or HTML.
Yes, CVE-2016-7033 can lead to data compromise as attackers can inject malicious scripts into the app.