CVE-2017-2658
published 2018-07-27CVE-2017-2658: It was discovered that the Dashbuilder login page as used in Red Hat JBoss BPM Suite before 6.4.2 and Red Hat JBoss Data Virtualization & Services before 6.4.3…
PriorityP432medium6.5CVSS 3.0
AVNACLPRNUIRSUCNIHAN
EPSS
1.48%
71.0th percentile
It was discovered that the Dashbuilder login page as used in Red Hat JBoss BPM Suite before 6.4.2 and Red Hat JBoss Data Virtualization & Services before 6.4.3 could be opened in an IFRAME, which made it possible to intercept and manipulate requests. An attacker could use this flaw to trick a user into performing arbitrary actions in the Console (clickjacking).
Affected
4 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| red_hat | bpms | — | — |
| red_hat | jdv | — | — |
| redhat | jboss_bpm_suite | < 6.4.2 | 6.4.2 |
| redhat | jboss_data_virtualization_services | < 6.4.3 | 6.4.3 |
CVSS provenance
nvdv3.06.5MEDIUMCVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:H/A:N
nvdv2.04.3MEDIUMAV:N/AC:M/Au:N/C:N/I:P/A:N
vendor_redhat2.6LOW
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Red Hat
Dashbuilder: Lack of clickjacking protection on the login page
vendor_redhat·2017-03-16·CVSS 2.6
CVE-2017-2658 [LOW] CWE-20 Dashbuilder: Lack of clickjacking protection on the login page
Dashbuilder: Lack of clickjacking protection on the login page
It was discovered that the Dashbuilder login page as used in Red Hat JBoss BPM Suite before 6.4.2 and Red Hat JBoss Data Virtualization & Services before 6.4.3 could be opened in an IFRAME, which made it possible to intercept and manipulate requests. An attacker could use this flaw to trick a user into performing arbitrary actions in the Console (clickjacking).
It was discovered that the Dashbuilder login page could be opened in an IFRAME, which made it possible to intercept and manipulate requests. An attacker could use this flaw to trick a user into performing arbitrary actions in the Console (clickjacking).
Package: dashbuilder (Red Hat BPM Suite 6) - Affected
GHSA
GHSA-8436-mv8f-g5vq: It was discovered that the Dashbuilder login page as used in Red Hat JBoss BPM Suite before 6
ghsa_unreviewed·2022-05-13
CVE-2017-2658 [MEDIUM] CWE-20 GHSA-8436-mv8f-g5vq: It was discovered that the Dashbuilder login page as used in Red Hat JBoss BPM Suite before 6
It was discovered that the Dashbuilder login page as used in Red Hat JBoss BPM Suite before 6.4.2 and Red Hat JBoss Data Virtualization & Services before 6.4.3 could be opened in an IFRAME, which made it possible to intercept and manipulate requests. An attacker could use this flaw to trick a user into performing arbitrary actions in the Console (clickjacking).
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2017-7592 libtiff: Left shift of unsigned char without a cast
bugzilla·2017-04-11·CVSS 7.8
CVE-2017-7592 [HIGH] CVE-2017-7592 libtiff: Left shift of unsigned char without a cast
CVE-2017-7592 libtiff: Left shift of unsigned char without a cast
The putagreytile function in tif_getimage.c in LibTIFF has a left-shift undefined behavior issue, which might allow attackers to cause a denial of service (application crash) via a crafted image.
Upstream bug:
http://bugzilla.maptools.org/show_bug.cgi?id=2658
Upstream patch:
https://github.com/vadz/libtiff/commit/48780b4fcc425cddc4ef8ffdf536f96a0d1b313b
Discussion:
Created mingw-libtiff tracking bugs for this issue:
Affects: fedora-all [bug 1438465]
---
Created mingw-libtiff tracking bugs for this issue:
Affects: epel-7 [bug 1438466]
---
Created libtiff tracking bugs for this issue:
Affects: fedora-all [bug 1441273]
Bugzilla
CVE-2017-2658 Dashbuilder: Lack of clickjacking protection on the login page
bugzilla·2017-03-16·CVSS 2.6
CVE-2017-2658 [LOW] CVE-2017-2658 Dashbuilder: Lack of clickjacking protection on the login page
CVE-2017-2658 Dashbuilder: Lack of clickjacking protection on the login page
It was discovered that the Dashbuilder login page could be opened in an IFRAME, which made it possible to intercept and manipulate requests. An attacker could use this flaw to trick a user into performing arbitrary actions in the Console (clickjacking).
Discussion:
Acknowledgments:
Name: Martin Weiler (Red Hat)
---
This issue has been addressed in the following products:
Red Hat JBoss BPM Suite 6.4.2
Via RHSA-2017:0557 https://rhn.redhat.com/errata/RHSA-2017-0557.html
---
This issue has been addressed in the following products:
Red Hat JBoss Data Virtualization
Via RHSA-2018:2243 https://access.redhat.com/errata/RHSA-2018:2243
http://rhn.redhat.com/errata/RHSA-2017-0557.htmlhttp://www.securityfocus.com/bid/97025https://access.redhat.com/errata/RHSA-2018:2243https://bugzilla.redhat.com/show_bug.cgi?id=CVE-2017-2658http://rhn.redhat.com/errata/RHSA-2017-0557.htmlhttp://www.securityfocus.com/bid/97025https://access.redhat.com/errata/RHSA-2018:2243https://bugzilla.redhat.com/show_bug.cgi?id=CVE-2017-2658
2018-07-27
Published