Description
Cross-site scripting (XSS) vulnerability in Business Process Editor in Red Hat JBoss BPM Suite before 6.3.3 allows remote authenticated users to inject arbitrary web script or HTML by levering permission to create business processes.
Remediation
References
http://rhn.redhat.com/errata/RHSA-2016-1968.html
http://rhn.redhat.com/errata/RHSA-2016-1969.html
http://www.securityfocus.com/bid/93219
https://bugzilla.redhat.com/show_bug.cgi?id=1358523
Related Vulnerabilities
CVE-2022-35924 Vulnerability in npm package next-auth
CVE-2019-3888 Vulnerability in maven package io.undertow:undertow-core
CVE-2023-46654 Vulnerability in maven package org.jenkins-ci.plugins:electricflow
CVE-2019-10076 Vulnerability in maven package org.apache.jspwiki:jspwiki-war
CVE-2019-16530 Vulnerability in maven package org.sonatype.nexus:nexus-core