4.3
CVSSv2

CVE-2017-7463

Published: 27/07/2018 Updated: 09/10/2019
CVSS v2 Base Score: 4.3 | Impact Score: 2.9 | Exploitability Score: 8.6
CVSS v3 Base Score: 6.1 | Impact Score: 2.7 | Exploitability Score: 2.8
VMScore: 383
Vector: AV:N/AC:M/Au:N/C:N/I:P/A:N

Vulnerability Summary

JBoss BRMS 6 and BPM Suite 6 prior to 6.4.3 are vulnerable to a reflected XSS via artifact upload. A malformed XML file, if uploaded, causes an error message to appear that includes part of the bad XML code verbatim without filtering out scripts. Successful exploitation would allow execution of script code within the context of the affected user.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

redhat jboss bpm suite

Vendor Advisories

JBoss BRMS 6 and BPM Suite 6 are vulnerable to a reflected XSS via artifact upload A malformed XML file, if uploaded, causes an error message to appear that includes part of the bad XML code verbatim without filtering out scripts Successful exploitation would allow execution of script code within the context of the affected user ...