JBPM KIE Workbench CVE-2013-6465 Multiple HTML Injection Vulnerabilities
BID:102313
Info
JBPM KIE Workbench CVE-2013-6465 Multiple HTML Injection Vulnerabilities
| Bugtraq ID: | 102313 |
| Class: | Input Validation Error |
| CVE: |
CVE-2013-6465 |
| Remote: | Yes |
| Local: | No |
| Published: | Dec 19 2017 12:00AM |
| Updated: | Dec 19 2017 12:00AM |
| Credit: | Grégory DRAPERI |
| Vulnerable: |
Redhat JBPM 6.0.0.Final Redhat JBPM 6.0.0.CR5 Redhat JBPM 6.0.0.CR4-Pre1 Redhat JBPM 6.0.0.CR4 Redhat JBPM 6.0.0.CR3 Redhat JBPM 6.0.0.CR2 Redhat JBPM 6.0.0.CR1 Redhat JBPM 6.0.0.Beta5 Redhat JBPM 6.0.0.Beta4 Redhat JBPM 6.0.0.Beta3 Redhat JBPM 6.0.0.Beta2 Redhat JBPM 6.0.0.Beta1 Redhat JBPM 6.0.0.Alpha9 Redhat JBPM 6.0.0.Alpha7 |
| Not Vulnerable: | |
Discussion
JBPM KIE Workbench CVE-2013-6465 Multiple HTML Injection Vulnerabilities
JBPM KIE is prone to multiple HTML-injection vulnerabilities.
Successful exploits will allow attacker-supplied HTML and script code to run in the context of the affected browser, potentially allowing the attacker to steal cookie-based authentication credentials or control how the site is rendered to the user. Other attacks are also possible.
JBPM KIE Workbench 6.0.x is vulnerable.
JBPM KIE is prone to multiple HTML-injection vulnerabilities.
Successful exploits will allow attacker-supplied HTML and script code to run in the context of the affected browser, potentially allowing the attacker to steal cookie-based authentication credentials or control how the site is rendered to the user. Other attacks are also possible.
JBPM KIE Workbench 6.0.x is vulnerable.
Exploit / POC
JBPM KIE Workbench CVE-2013-6465 Multiple HTML Injection Vulnerabilities
Attackers can exploit these issues using browser.
Attackers can exploit these issues using browser.
Solution / Fix
JBPM KIE Workbench CVE-2013-6465 Multiple HTML Injection Vulnerabilities
Solution:
Updates are available. Please see the references or vendor advisory for more information.
Solution:
Updates are available. Please see the references or vendor advisory for more information.
References
JBPM KIE Workbench CVE-2013-6465 Multiple HTML Injection Vulnerabilities
References:
References:
- KIE Homepage (kiegroup)
- Redhat Homepage (redhat)
- CVE-2013-6465 (redhat)
- JBPM KIE Workbench: Multiple stored XSS issues (redhat)