Severity
4.3MEDIUM
EPSS
1.3%
top 20.48%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedFeb 5
Latest updateMay 17

Description

Cross-site scripting (XSS) vulnerability in the JMX console in JBoss Enterprise Application Platform (EAP) before 5.2.0, Web Platform (EWP) before 5.2.0, BRMS Platform before 5.3.1, and SOA Platform before 5.3.1 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.

CVSS vector

AV:N/AC:M/C:N/I:P/A:NExploitability: 8.6 | Impact: 2.9

🔴Vulnerability Details

2
GHSA
GHSA-v4j8-rhv4-55m7: Cross-site scripting (XSS) vulnerability in the JMX console in JBoss Enterprise Application Platform (EAP) before 52022-05-17
CVEList
CVE-2011-4575: Cross-site scripting (XSS) vulnerability in the JMX console in JBoss Enterprise Application Platform (EAP) before 52013-02-05

📋Vendor Advisories

1
Red Hat
Console: XSS in invoke operation2013-01-24

💬Community

1
Bugzilla
CVE-2011-4575 JMX Console: XSS in invoke operation2011-12-06
CVE-2011-4575 (MEDIUM CVSS 4.3) | Cross-site scripting (XSS) vulnerab | cvebase.io