CVE-2017-2674
published 2018-07-27CVE-2017-2674: JBoss BRMS 6 and BPM Suite 6 before 6.4.3 are vulnerable to a stored XSS via several lists in Business Central. The flaw is due to lack of sanitation of user…
PriorityP427medium5.4CVSS 3.0
AVNACLPRLUIRSCCLILAN
EPSS
1.29%
67.1th percentile
JBoss BRMS 6 and BPM Suite 6 before 6.4.3 are vulnerable to a stored XSS via several lists in Business Central. The flaw is due to lack of sanitation of user input when creating new lists. Remote, authenticated attackers that have privileges to create lists can store scripts in them, which are not properly sanitized before showing to other users, including admins.
Affected
2 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| red_hat | business-central | — | — |
| redhat | jboss_bpm_suite | >= 6.0.0 < 6.4.3 | 6.4.3 |
CVSS provenance
nvdv3.05.4MEDIUMCVSS:3.0/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N
nvdv2.03.5LOWAV:N/AC:M/Au:S/C:N/I:P/A:N
vendor_redhat6.1MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Red Hat
business-central: Multiple stored XSS in task and process filters
vendor_redhat·2017-02-10·CVSS 6.1
CVE-2017-2674 [MEDIUM] CWE-20 business-central: Multiple stored XSS in task and process filters
business-central: Multiple stored XSS in task and process filters
JBoss BRMS 6 and BPM Suite 6 before 6.4.3 are vulnerable to a stored XSS via several lists in Business Central. The flaw is due to lack of sanitation of user input when creating new lists. Remote, authenticated attackers that have privileges to create lists can store scripts in them, which are not properly sanitized before showing to other users, including admins.
JBoss BRMS 6 and BPM Suite 6 are vulnerable to a stored XSS via several lists in Business Central. The flaw is due to lack of sanitation of user input when creating new lists. Remote, authenticated attackers that have privileges to create lists can store scripts in them, which are not properly sanitized before showing to other users, including admins.
GHSA
GHSA-5xrw-c22r-9h93: JBoss BRMS 6 and BPM Suite 6 before 6
ghsa_unreviewed·2022-05-13
CVE-2017-2674 [MEDIUM] CWE-79 GHSA-5xrw-c22r-9h93: JBoss BRMS 6 and BPM Suite 6 before 6
JBoss BRMS 6 and BPM Suite 6 before 6.4.3 are vulnerable to a stored XSS via several lists in Business Central. The flaw is due to lack of sanitation of user input when creating new lists. Remote, authenticated attackers that have privileges to create lists can store scripts in them, which are not properly sanitized before showing to other users, including admins.
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2017-7554 RHMAP: Stored XSS in App Store
bugzilla·2017-08-07·CVSS 6.1
CVE-2017-7554 [MEDIUM] CVE-2017-7554 RHMAP: Stored XSS in App Store
CVE-2017-7554 RHMAP: Stored XSS in App Store
It was found that the App Studio component of RHMAP 4.4 executes javascript provided by a user. An attacker could use this flaw to execute a stored XSS attack on an application administrator using App Studio.
Discussion:
Acknowledgments:
Name: Tomas Rzepka
---
Fixed in 4.5.0
---
This issue has been addressed in the following products:
Red Hat Mobile Application Platform 4.5
Via RHSA-2017:2675 https://access.redhat.com/errata/RHSA-2017:2675
---
This issue has been addressed in the following products:
Red Hat Mobile Application Platform 4.5
Via RHSA-2017:2674 https://access.redhat.com/errata/RHSA-2017:2674
Bugzilla
CVE-2017-7553 RHMAP: SSRF via external_request feature of App Studio
bugzilla·2017-08-07·CVSS 6.3
CVE-2017-7553 [MEDIUM] CVE-2017-7553 RHMAP: SSRF via external_request feature of App Studio
CVE-2017-7553 RHMAP: SSRF via external_request feature of App Studio
The external_request api call in App Studio (millicore) allows server side request forgery (SSRF). An attacker could use this flaw to probe the network internal resources, and access restriced endpoints.
Discussion:
Acknowledgments:
Name: Tomas Rzepka
---
This issue has been addressed in the following products:
Red Hat Mobile Application Platform 4.5
Via RHSA-2017:2675 https://access.redhat.com/errata/RHSA-2017:2675
---
This issue has been addressed in the following products:
Red Hat Mobile Application Platform 4.5
Via RHSA-2017:2674 https://access.redhat.com/errata/RHSA-2017:2674
Bugzilla
CVE-2017-7552 RHMAP Millicore IDE allows RCE on SCM
bugzilla·2017-08-03·CVSS 9.8
CVE-2017-7552 [CRITICAL] CVE-2017-7552 RHMAP Millicore IDE allows RCE on SCM
CVE-2017-7552 RHMAP Millicore IDE allows RCE on SCM
The file editor in millicore allows files to be executed, as well as created. An attacker could use this flaw to compromise other users, or teams projects stored in source control managment of the RHMAP Core installation.
Discussion:
Acknowledgments:
Name: Tomas Rzepka
---
This issue has been addressed in the following products:
Red Hat Mobile Application Platform 4.5
Via RHSA-2017:2675 https://access.redhat.com/errata/RHSA-2017:2675
---
This issue has been addressed in the following products:
Red Hat Mobile Application Platform 4.5
Via RHSA-2017:2674 https://access.redhat.com/errata/RHSA-2017:2674
Bugzilla
CVE-2017-2674 business-central: Multiple stored XSS in task and process filters
bugzilla·2017-04-06·CVSS 6.1
CVE-2017-2674 [MEDIUM] CVE-2017-2674 business-central: Multiple stored XSS in task and process filters
CVE-2017-2674 business-central: Multiple stored XSS in task and process filters
It was found that Task Filter List in business central accepts HTML tags in the Name field. When creating a new task filtered list with crafted Name field and deleting it, HTML code is rendered.
Upstream bug:
https://issues.jboss.org/browse/RHBPMS-4625
Discussion:
Acknowledgments:
Name: Chris Hebert, Vikas Pandey, Harold Schliesske, Ryan Stanley (Noblis)
---
This issue has been addressed in the following products:
Red Hat JBoss BPM Suite 6.4.3
Via RHSA-2017:1218 https://access.redhat.com/errata/RHSA-2017:1218
---
This issue has been addressed in the following products:
Red Hat JBoss BRMS 6.4.3
Via RHSA-2017:1217 https://access.redhat.com/errata/RHSA-2017:1217
http://www.securityfocus.com/bid/98390https://access.redhat.com/errata/RHSA-2017:1217https://access.redhat.com/errata/RHSA-2017:1218https://bugzilla.redhat.com/show_bug.cgi?id=CVE-2017-2674http://www.securityfocus.com/bid/98390https://access.redhat.com/errata/RHSA-2017:1217https://access.redhat.com/errata/RHSA-2017:1218https://bugzilla.redhat.com/show_bug.cgi?id=CVE-2017-2674
2018-07-27
Published