First published: Thu Apr 06 2017(Updated: )
It was found that Task Filter List in business central accepts HTML tags in the Name field. When creating a new task filtered list with crafted Name field and deleting it, HTML code is rendered. Upstream bug: <a href="https://issues.jboss.org/browse/RHBPMS-4625">https://issues.jboss.org/browse/RHBPMS-4625</a>
Credit: secalert@redhat.com
Affected Software | Affected Version | How to fix |
---|---|---|
redhat/BPMS | <6.4.3 | 6.4.3 |
redhat/BRMS | <6.4.3 | 6.4.3 |
redhat JBoss BPM suite | >=6.0.0<6.4.3 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The severity of CVE-2017-2674 is classified as moderate.
To fix CVE-2017-2674, you need to upgrade to BPMS or BRMS version 6.4.3 or later.
CVE-2017-2674 affects Red Hat JBoss BPM Suite versions between 6.0.0 and 6.4.3.
CVE-2017-2674 exploits the acceptance of HTML tags in the Name field of the Task Filter List.
There is no official workaround for CVE-2017-2674; upgrading is the recommended approach.