This CPE summary could be partial or incomplete. Please contact us for a detailed listing.

Summary

Detail
Vendor Redhat First view 2014-04-10
Product Jboss Bpm Suite Last view 2018-10-31
Version 6.0.0 Type Application
Update *  
Edition *  
Language *  
Sofware Edition *  
Target Software *  
Target Hardware *  
Other *  
 
CPE Product cpe:2.3:a:redhat:jboss_bpm_suite

Activity : Overall

Related : CVE

  Date Alert Description
5.4 2018-10-31 CVE-2016-6343

JBoss BPM Suite 6 is vulnerable to a reflected XSS via dashbuilder. Remote attackers can entice authenticated users that have privileges to access dashbuilder (usually admins) to click on links to /dashbuilder/Controller containing malicious scripts. Successful exploitation would allow execution of script code within the context of the affected user.

5.4 2018-08-01 CVE-2016-8608

JBoss BRMS 6 and BPM Suite 6 are vulnerable to a stored XSS via business process editor. The flaw is due to an incomplete fix for CVE-2016-5398. Remote, authenticated attackers that have privileges to create business processes can store scripts in them, which are not properly sanitized before showing to other users, including admins.

6.1 2018-07-27 CVE-2017-7463

JBoss BRMS 6 and BPM Suite 6 before 6.4.3 are vulnerable to a reflected XSS via artifact upload. A malformed XML file, if uploaded, causes an error message to appear that includes part of the bad XML code verbatim without filtering out scripts. Successful exploitation would allow execution of script code within the context of the affected user.

5.4 2018-07-27 CVE-2017-2674

JBoss BRMS 6 and BPM Suite 6 before 6.4.3 are vulnerable to a stored XSS via several lists in Business Central. The flaw is due to lack of sanitation of user input when creating new lists. Remote, authenticated attackers that have privileges to create lists can store scripts in them, which are not properly sanitized before showing to other users, including admins.

6.5 2018-07-27 CVE-2017-2658

It was discovered that the Dashbuilder login page as used in Red Hat JBoss BPM Suite before 6.4.2 and Red Hat JBoss Data Virtualization & Services before 6.4.3 could be opened in an IFRAME, which made it possible to intercept and manipulate requests. An attacker could use this flaw to trick a user into performing arbitrary actions in the Console (clickjacking).

9.8 2017-11-09 CVE-2015-7501

Red Hat JBoss A-MQ 6.x; BPM Suite (BPMS) 6.x; BRMS 6.x and 5.x; Data Grid (JDG) 6.x; Data Virtualization (JDV) 6.x and 5.x; Enterprise Application Platform 6.x, 5.x, and 4.3.x; Fuse 6.x; Fuse Service Works (FSW) 6.x; Operations Network (JBoss ON) 3.x; Portal 6.x; SOA Platform (SOA-P) 5.x; Web Server (JWS) 3.x; Red Hat OpenShift/xPAAS 3.x; and Red Hat Subscription Asset Manager 1.3 allow remote attackers to execute arbitrary commands via a crafted serialized Java object, related to the Apache Commons Collections (ACC) library.

8.8 2017-04-20 CVE-2016-5401

Cross-site request forgery (CSRF) vulnerability in Red Hat JBoss BRMS and BPMS 6 allows remote attackers to hijack the authentication of users for requests that modify instances via a crafted web page.

5.4 2016-10-03 CVE-2016-5398

Cross-site scripting (XSS) vulnerability in Business Process Editor in Red Hat JBoss BPM Suite before 6.3.3 allows remote authenticated users to inject arbitrary web script or HTML by levering permission to create business processes.

9.8 2016-08-05 CVE-2016-4999

SQL injection vulnerability in the getStringParameterSQL method in main/java/org/dashbuilder/dataprovider/sql/dialect/DefaultDialect.java in Dashbuilder before 0.6.0.Beta1 allows remote attackers to execute arbitrary SQL commands via a data set lookup filter in the (1) Data Set Authoring or (2) Displayer editor UI.

7.5 2015-08-11 CVE-2015-1818

XML external entity (XXE) vulnerability in the dashbuilder import facility (DocumentBuilders in org.jboss.dashboard.export.ImportManagerImpl) in Red Hat JBoss BPM Suite before 6.1.2 allows remote attackers to read arbitrary files, conduct server-side request forgery (SSRF) attacks, and have other unspecified impact via a crafted XML document.

6.5 2014-04-10 CVE-2013-6468

JBoss Drools, Red Hat JBoss BRMS before 6.0.1, and Red Hat JBoss BPM Suite before 6.0.1 allows remote authenticated users to execute arbitrary Java code via a (1) MVFLEX Expression Language (MVEL) or (2) Drools expression.

CWE : Common Weakness Enumeration

%idName
42% (3) CWE-79 Failure to Preserve Web Page Structure ('Cross-site Scripting')
14% (1) CWE-502 Deserialization of Untrusted Data
14% (1) CWE-352 Cross-Site Request Forgery (CSRF)
14% (1) CWE-94 Failure to Control Generation of Code ('Code Injection')
14% (1) CWE-89 Improper Sanitization of Special Elements used in an SQL Command ('...

Snort® IPS/IDS

Date Description
2014-01-10 XML entity parsing information disclosure attempt
RuleID : 24339 - Type : SERVER-WEBAPP - Revision : 14

Nessus® Vulnerability Scanner

This CPE have more than 25 Relations. If you want to see a complete summary for this CPE, please contact us.
id Description
2018-03-21 Name: The remote device is affected by multiple vulnerabilities.
File: juniper_space_jsa_10838.nasl - Type: ACT_GATHER_INFO
2017-01-25 Name: A web application running on the remote host is affected by multiple vulnerab...
File: mysql_enterprise_monitor_3_2_2_1075.nasl - Type: ACT_GATHER_INFO
2017-01-25 Name: A web application running on the remote host is affected by a remote code exe...
File: mysql_enterprise_monitor_3_1_6_7959.nasl - Type: ACT_GATHER_INFO
2016-10-26 Name: An application server installed on the remote host is affected by multiple vu...
File: oracle_weblogic_server_cpu_oct_2016.nasl - Type: ACT_GATHER_INFO
2016-05-03 Name: The remote host has a web application installed that is affected by a remote ...
File: oracle_oats_cpu_apr_2016.nasl - Type: ACT_GATHER_INFO
2016-01-11 Name: The remote Red Hat host is missing one or more security updates.
File: redhat-RHSA-2015-2540.nasl - Type: ACT_GATHER_INFO
2015-12-22 Name: The remote Scientific Linux host is missing one or more security updates.
File: sl_20151221_jakarta_commons_collections_on_SL5_x.nasl - Type: ACT_GATHER_INFO
2015-12-22 Name: The remote Oracle Linux host is missing one or more security updates.
File: oraclelinux_ELSA-2015-2671.nasl - Type: ACT_GATHER_INFO
2015-12-22 Name: The remote CentOS host is missing one or more security updates.
File: centos_RHSA-2015-2671.nasl - Type: ACT_GATHER_INFO
2015-12-21 Name: The remote Red Hat host is missing one or more security updates.
File: redhat-RHSA-2015-2671.nasl - Type: ACT_GATHER_INFO
2015-12-15 Name: The remote Amazon Linux AMI host is missing a security update.
File: ala_ALAS-2015-618.nasl - Type: ACT_GATHER_INFO
2015-12-10 Name: The remote JBoss server is affected by multiple remote code execution vulnera...
File: jboss_java_serialize.nasl - Type: ACT_ATTACK
2015-12-04 Name: The remote Red Hat host is missing one or more security updates.
File: redhat-RHSA-2015-2542.nasl - Type: ACT_GATHER_INFO
2015-12-04 Name: The remote Red Hat host is missing one or more security updates.
File: redhat-RHSA-2015-2539.nasl - Type: ACT_GATHER_INFO
2015-12-04 Name: The remote Red Hat host is missing one or more security updates.
File: redhat-RHSA-2015-2538.nasl - Type: ACT_GATHER_INFO
2015-12-04 Name: The remote Red Hat host is missing a security update.
File: redhat-RHSA-2015-2536.nasl - Type: ACT_GATHER_INFO
2015-12-04 Name: The remote Red Hat host is missing one or more security updates.
File: redhat-RHSA-2015-2535.nasl - Type: ACT_GATHER_INFO
2015-12-03 Name: The remote Red Hat host is missing one or more security updates.
File: redhat-RHSA-2015-2522.nasl - Type: ACT_GATHER_INFO
2015-12-03 Name: The remote CentOS host is missing one or more security updates.
File: centos_RHSA-2015-2521.nasl - Type: ACT_GATHER_INFO
2015-12-02 Name: The remote CentOS host is missing one or more security updates.
File: centos_RHSA-2015-2522.nasl - Type: ACT_GATHER_INFO
2015-12-01 Name: The remote Scientific Linux host is missing one or more security updates.
File: sl_20151130_jakarta_commons_collections_on_SL6_x.nasl - Type: ACT_GATHER_INFO
2015-12-01 Name: The remote Scientific Linux host is missing one or more security updates.
File: sl_20151130_apache_commons_collections_on_SL7_x.nasl - Type: ACT_GATHER_INFO
2015-12-01 Name: The remote Oracle Linux host is missing one or more security updates.
File: oraclelinux_ELSA-2015-2522.nasl - Type: ACT_GATHER_INFO
2015-12-01 Name: The remote Oracle Linux host is missing one or more security updates.
File: oraclelinux_ELSA-2015-2521.nasl - Type: ACT_GATHER_INFO
2015-11-30 Name: The remote Red Hat host is missing one or more security updates.
File: redhat-RHSA-2015-2521.nasl - Type: ACT_GATHER_INFO