Description
Cross-site scripting (XSS) vulnerability in Business Process Editor in Red Hat JBoss BPM Suite before 6.3.3 allows remote authenticated users to inject arbitrary web script or HTML by levering permission to create business processes.
Remediation
References
http://rhn.redhat.com/errata/RHSA-2016-1968.html
http://rhn.redhat.com/errata/RHSA-2016-1969.html
http://www.securityfocus.com/bid/93219
https://bugzilla.redhat.com/show_bug.cgi?id=1358523
Related Vulnerabilities
CVE-2021-31684 Vulnerability in maven package net.minidev:json-smart
CVE-2022-32287 Vulnerability in maven package org.apache.uima:uimaj-core
CVE-2013-7454 Vulnerability in npm package validator
CVE-2017-7957 Vulnerability in maven package org.jvnet.hudson:xstream
CVE-2023-30535 Vulnerability in maven package net.snowflake:snowflake-jdbc