Description
Cross-site scripting (XSS) vulnerability in Business Process Editor in Red Hat JBoss BPM Suite before 6.3.3 allows remote authenticated users to inject arbitrary web script or HTML by levering permission to create business processes.
Remediation
References
http://rhn.redhat.com/errata/RHSA-2016-1968.html
http://rhn.redhat.com/errata/RHSA-2016-1969.html
http://www.securityfocus.com/bid/93219
https://bugzilla.redhat.com/show_bug.cgi?id=1358523
Related Vulnerabilities
CVE-2023-31206 Vulnerability in maven package org.apache.inlong:manager-dao
CVE-2023-28155 Vulnerability in maven package org.webjars.npm:request
CVE-2020-6460 Vulnerability in maven package org.webjars.npm:electron
CVE-2023-28935 Vulnerability in maven package org.apache.uima:uima-ducc-parent
CVE-2023-25762 Vulnerability in maven package org.jenkins-ci.plugins:pipeline-build-step