CVE-2016-5398
published 2016-10-03CVE-2016-5398: Cross-site scripting (XSS) vulnerability in Business Process Editor in Red Hat JBoss BPM Suite before 6.3.3 allows remote authenticated users to inject…
PriorityP422medium5.4CVSS 3.0
AVNACLPRLUIRSCCLILAN
EPSS
0.85%
54.0th percentile
Cross-site scripting (XSS) vulnerability in Business Process Editor in Red Hat JBoss BPM Suite before 6.3.3 allows remote authenticated users to inject arbitrary web script or HTML by levering permission to create business processes.
Affected
4 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| red_hat | brms | — | — |
| redhat | jboss_bpm_suite | <= 6.3.2 | — |
| redhat | jboss_bpm_suite | — | — |
| redhat | jboss_business_rules_management_system | — | — |
CVSS provenance
nvdv3.05.4MEDIUMCVSS:3.0/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N
nvdv2.03.5LOWAV:N/AC:M/Au:S/C:N/I:P/A:N
vendor_redhat5.4MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-c556-333h-3frm: Cross-site scripting (XSS) vulnerability in Business Process Editor in Red Hat JBoss BPM Suite before 6
ghsa_unreviewed·2022-05-17
CVE-2016-5398 [MEDIUM] CWE-79 GHSA-c556-333h-3frm: Cross-site scripting (XSS) vulnerability in Business Process Editor in Red Hat JBoss BPM Suite before 6
Cross-site scripting (XSS) vulnerability in Business Process Editor in Red Hat JBoss BPM Suite before 6.3.3 allows remote authenticated users to inject arbitrary web script or HTML by levering permission to create business processes.
GHSA
GHSA-9vxf-m4pg-2r4f: JBoss BRMS 6 and BPM Suite 6 are vulnerable to a stored XSS via business process editor
ghsa_unreviewed·2022-05-13·CVSS 5.4
CVE-2016-8608 [MEDIUM] CWE-79 GHSA-9vxf-m4pg-2r4f: JBoss BRMS 6 and BPM Suite 6 are vulnerable to a stored XSS via business process editor
JBoss BRMS 6 and BPM Suite 6 are vulnerable to a stored XSS via business process editor. The flaw is due to an incomplete fix for CVE-2016-5398. Remote, authenticated attackers that have privileges to create business processes can store scripts in them, which are not properly sanitized before showing to other users, including admins.
Red Hat
Stored XSS in business process editor
vendor_redhat·2016-11-28·CVSS 5.4
CVE-2016-8608 [MEDIUM] CWE-79 Stored XSS in business process editor
Stored XSS in business process editor
JBoss BRMS 6 and BPM Suite 6 are vulnerable to a stored XSS via business process editor. The flaw is due to an incomplete fix for CVE-2016-5398. Remote, authenticated attackers that have privileges to create business processes can store scripts in them, which are not properly sanitized before showing to other users, including admins.
JBoss BRMS 6 and BPM Suite 6 are vulnerable to a stored XSS via business process editor. The flaw is due to an incomplete fix for CVE-2016-5398. Remote, authenticated attackers that have privileges to create business processes can store scripts in them, which are not properly sanitized before showing to other users, including admins.
Package: process-editor (Red Hat BPM Suite 6) - Affected
Package: process-editor (Red
Red Hat
stored XSS in JBoss BPM suite business process editor
vendor_redhat·2016-09-28·CVSS 5.4
CVE-2016-5398 [MEDIUM] CWE-79 stored XSS in JBoss BPM suite business process editor
stored XSS in JBoss BPM suite business process editor
Cross-site scripting (XSS) vulnerability in Business Process Editor in Red Hat JBoss BPM Suite before 6.3.3 allows remote authenticated users to inject arbitrary web script or HTML by levering permission to create business processes.
A security flaw was found in the way Business Process Editor displays the business process details to the user. A remote authenticated attacker with privilege to create business processes could use this flaw to conduct stored XSS attacks against other users.
Package: business-central (Red Hat BPM Suite 6) - Affected
Package: business-central (Red Hat JBoss BRMS 6) - Affected
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2016-8608 Stored XSS in business process editor
bugzilla·2016-10-19·CVSS 5.4
CVE-2016-8608 [MEDIUM] CVE-2016-8608 Stored XSS in business process editor
CVE-2016-8608 Stored XSS in business process editor
JBoss BRMS 6 and BPM Suite 6 are vulnerable to a stored XSS via business process editor. The flaw is due to an incomplete fix for CVE-2016-5398. Remote authenticated attackers that have privileges to create business processes can store scripts in them, which are not properly sanitized before showing to other users, including admins.
Discussion:
Acknowledgments:
Name: Kirill Gaevskii (Red Hat)
---
This issue has been addressed in the following products:
Red Hat JBoss BRMS 6.4.0
Via RHSA-2016:2823 https://rhn.redhat.com/errata/RHSA-2016-2823.html
---
This issue has been addressed in the following products:
Red Hat JBoss BPM Suite 6.4.0
Via RHSA-2016:2822 https://rhn.redhat.com/errata/RHSA-2016-2822.html
Bugzilla
CVE-2016-5398 stored XSS in JBoss BPM suite business process editor
bugzilla·2016-07-20·CVSS 5.4
CVE-2016-5398 [MEDIUM] CVE-2016-5398 stored XSS in JBoss BPM suite business process editor
CVE-2016-5398 stored XSS in JBoss BPM suite business process editor
JBoss BPM Suite 6.3.0 is vulnerable to a stored XSS via business process
editor. Remote authenticated attackers that have privileges to create business processes can store scripts in them, which are not properly sanitized before showing to other users, including admins.
Discussion:
Acknowledgments:
Name: Jeremy Choi (Red Hat Product Security Team)
---
This issue has been addressed in the following products:
Red Hat JBoss BPM Suite 6.3.3
Via RHSA-2016:1969 https://rhn.redhat.com/errata/RHSA-2016-1969.html
---
This issue has been addressed in the following products:
Red Hat JBoss BRMS 6.3.3
Via RHSA-2016:1968 https://rhn.redhat.com/errata/RHSA-2016-1968.html
http://rhn.redhat.com/errata/RHSA-2016-1968.htmlhttp://rhn.redhat.com/errata/RHSA-2016-1969.htmlhttp://www.securityfocus.com/bid/93219https://bugzilla.redhat.com/show_bug.cgi?id=1358523http://rhn.redhat.com/errata/RHSA-2016-1968.htmlhttp://rhn.redhat.com/errata/RHSA-2016-1969.htmlhttp://www.securityfocus.com/bid/93219https://bugzilla.redhat.com/show_bug.cgi?id=1358523
2016-10-03
Published