ServerAdmin/ErrorViewer.jsp in DS3 Authentication Server allow remote malicious users to inject arbitrary error-page text via the message parameter.
ds3 authentication server -