Cross-site scripting (XSS) vulnerability in the JMX console in JBoss Enterprise Application Platform (EAP) before 5.2.0, Web Platform (EWP) before 5.2.0, BRMS Platform before 5.3.1, and SOA Platform before 5.3.1 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.
The product receives input or data, but it does not validate or incorrectly validates that the input has the properties that are required to process the data safely and correctly.
Link | Tags |
---|---|
https://bugzilla.redhat.com/show_bug.cgi?id=760387 | |
http://www.osvdb.org/89578 | vdb entry |
http://rhn.redhat.com/errata/RHSA-2013-0192.html | vendor advisory |
http://rhn.redhat.com/errata/RHSA-2013-0198.html | vendor advisory |
http://rhn.redhat.com/errata/RHSA-2013-0195.html | vendor advisory |
http://rhn.redhat.com/errata/RHSA-2013-0221.html | vendor advisory |
http://rhn.redhat.com/errata/RHSA-2013-0196.html | vendor advisory |
http://rhn.redhat.com/errata/RHSA-2013-0193.html | vendor advisory |
http://secunia.com/advisories/51984 | third party advisory vendor advisory |
http://secunia.com/advisories/52054 | third party advisory vendor advisory |
http://rhn.redhat.com/errata/RHSA-2013-0191.html | vendor advisory |
http://rhn.redhat.com/errata/RHSA-2013-0197.html | vendor advisory |
http://rhn.redhat.com/errata/RHSA-2013-0194.html | vendor advisory |
http://www.securityfocus.com/bid/57548 | vdb entry |