Known Vulnerabilities for Jboss Bpm Suite by Redhat
Listed below are 10 of the newest known vulnerabilities associated with "Jboss Bpm Suite" by "Redhat".
These CVEs are retrieved based on exact matches on listed software, hardware, and vendor information (CPE data) as well as a keyword search to ensure the newest vulnerabilities with no officially listed software information are still displayed.
Data on known vulnerable versions is also displayed based on information from known CPEs
Known Vulnerabilities
| CVE | Shortened Description | Severity | Publish Date | Last Modified |
|---|---|---|---|---|
| CVE-2018-19362 | FasterXML jackson-databind 2.x before 2.9.8 might allow attackers to have unspecified impact by leveraging failure to block t... | 9.8 - CRITICAL | 2019-01-02 | 2023-11-07 |
| CVE-2018-19361 | FasterXML jackson-databind 2.x before 2.9.8 might allow attackers to have unspecified impact by leveraging failure to block t... | 9.8 - CRITICAL | 2019-01-02 | 2023-11-07 |
| CVE-2018-19360 | FasterXML jackson-databind 2.x before 2.9.8 might allow attackers to have unspecified impact by leveraging failure to block t... | 9.8 - CRITICAL | 2019-01-02 | 2023-11-07 |
| CVE-2017-7545 | It was discovered that the XmlUtils class in jbpmmigration 6.5 performed expansion of external parameter entities while parsi... | 6.5 - MEDIUM | 2018-07-26 | 2019-10-09 |
| CVE-2017-7463 | JBoss BRMS 6 and BPM Suite 6 before 6.4.3 are vulnerable to a reflected XSS via artifact upload. A malformed XML file, if upl... | 6.1 - MEDIUM | 2018-07-27 | 2019-10-09 |
| CVE-2017-2674 | JBoss BRMS 6 and BPM Suite 6 before 6.4.3 are vulnerable to a stored XSS via several lists in Business Central. The flaw is d... | 5.4 - MEDIUM | 2018-07-27 | 2019-10-09 |
| CVE-2017-2658 | It was discovered that the Dashbuilder login page as used in Red Hat JBoss BPM Suite before 6.4.2 and Red Hat JBoss Data Virt... | 6.5 - MEDIUM | 2018-07-27 | 2023-02-12 |
| CVE-2016-5401 | Cross-site request forgery (CSRF) vulnerability in Red Hat JBoss BRMS and BPMS 6 allows remote attackers to hijack the authen... | 8.8 - HIGH | 2017-04-20 | 2017-04-26 |
| CVE-2016-5398 | Cross-site scripting (XSS) vulnerability in Business Process Editor in Red Hat JBoss BPM Suite before 6.3.3 allows remote aut... | 5.4 - MEDIUM | 2016-10-03 | 2016-10-04 |
| CVE-2016-4999 | SQL injection vulnerability in the getStringParameterSQL method in main/java/org/dashbuilder/dataprovider/sql/dialect/Default... | 9.8 - CRITICAL | 2016-08-05 | 2021-04-27 |
Known Affected Configurations (CPE V2.3)
| Type | Vendor | Product | Version | Update | Edition | Language |
|---|---|---|---|---|---|---|
| Application | Redhat | Jboss Bpm Suite | 6.4.3 | All | All | All |
| Application | Redhat | Jboss Bpm Suite | 6.4.12 | All | All | All |
| Application | Redhat | Jboss Bpm Suite | 6.4.11 | All | All | All |
| Application | Redhat | Jboss Bpm Suite | 6.4 | All | All | All |
| Application | Redhat | Jboss Bpm Suite | 6.3.2 | All | All | All |
| Application | Redhat | Jboss Bpm Suite | 6.3 | All | All | All |
| Application | Redhat | Jboss Bpm Suite | 6.2 | All | All | All |
| Application | Redhat | Jboss Bpm Suite | 6.0.1 | All | All | All |
| Application | Redhat | Jboss Bpm Suite | 6.0.0 | All | All | All |