CVE-2017-7463
published 2018-07-27CVE-2017-7463: JBoss BRMS 6 and BPM Suite 6 before 6.4.3 are vulnerable to a reflected XSS via artifact upload. A malformed XML file, if uploaded, causes an error message to…
PriorityP425medium6.1CVSS 3.0
AVNACLPRNUIRSCCLILAN
EPSS
1.82%
76.3th percentile
JBoss BRMS 6 and BPM Suite 6 before 6.4.3 are vulnerable to a reflected XSS via artifact upload. A malformed XML file, if uploaded, causes an error message to appear that includes part of the bad XML code verbatim without filtering out scripts. Successful exploitation would allow execution of script code within the context of the affected user.
Affected
2 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| red_hat | business-central | — | — |
| redhat | jboss_bpm_suite | >= 6.0.0 < 6.4.3 | 6.4.3 |
CVSS provenance
nvdv3.06.1MEDIUMCVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
nvdv2.04.3MEDIUMAV:N/AC:M/Au:N/C:N/I:P/A:N
vendor_redhat6.1MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-65vp-3wr6-gx6m: JBoss BRMS 6 and BPM Suite 6 before 6
ghsa_unreviewed·2022-05-13
CVE-2017-7463 [MEDIUM] CWE-79 GHSA-65vp-3wr6-gx6m: JBoss BRMS 6 and BPM Suite 6 before 6
JBoss BRMS 6 and BPM Suite 6 before 6.4.3 are vulnerable to a reflected XSS via artifact upload. A malformed XML file, if uploaded, causes an error message to appear that includes part of the bad XML code verbatim without filtering out scripts. Successful exploitation would allow execution of script code within the context of the affected user.
Red Hat
business-central: Reflected XSS in artifact upload error message
vendor_redhat·2017-02-13·CVSS 6.1
CVE-2017-7463 [MEDIUM] CWE-79 business-central: Reflected XSS in artifact upload error message
business-central: Reflected XSS in artifact upload error message
JBoss BRMS 6 and BPM Suite 6 before 6.4.3 are vulnerable to a reflected XSS via artifact upload. A malformed XML file, if uploaded, causes an error message to appear that includes part of the bad XML code verbatim without filtering out scripts. Successful exploitation would allow execution of script code within the context of the affected user.
JBoss BRMS 6 and BPM Suite 6 are vulnerable to a reflected XSS via artifact upload. A malformed XML file, if uploaded, causes an error message to appear that includes part of the bad XML code verbatim without filtering out scripts. Successful exploitation would allow execution of script code within the context of the affected user.
No detection rules found.
No public exploits indexed.
http://www.securityfocus.com/bid/98385https://access.redhat.com/errata/RHSA-2017:1217https://access.redhat.com/errata/RHSA-2017:1218https://bugzilla.redhat.com/show_bug.cgi?id=CVE-2017-7463http://www.securityfocus.com/bid/98385https://access.redhat.com/errata/RHSA-2017:1217https://access.redhat.com/errata/RHSA-2017:1218https://bugzilla.redhat.com/show_bug.cgi?id=CVE-2017-7463
2018-07-27
Published