Description
Cross-site scripting (XSS) vulnerability in Business Process Editor in Red Hat JBoss BPM Suite before 6.3.3 allows remote authenticated users to inject arbitrary web script or HTML by levering permission to create business processes.
Remediation
References
http://rhn.redhat.com/errata/RHSA-2016-1968.html
http://rhn.redhat.com/errata/RHSA-2016-1969.html
http://www.securityfocus.com/bid/93219
https://bugzilla.redhat.com/show_bug.cgi?id=1358523
Related Vulnerabilities
CVE-2013-1965 Vulnerability in maven package org.apache.struts:struts2-showcase
CVE-2017-1000402 Vulnerability in maven package org.jenkins-ci.plugins:swarm-plugin
CVE-2020-6452 Vulnerability in maven package org.webjars.npm:electron
CVE-2022-23510 Vulnerability in npm package @cubejs-backend/api-gateway
CVE-2016-6816 Vulnerability in maven package org.apache.tomcat:coyote