Vulnerability index

Browse CVEs

104 matching
Filters 2 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Cross-site Scripting (XSS)CWE-79 × clear
Jboss Enterprise Application Platform CRITICAL 9.0
CVE-2019-3873

It was found that Picketlink as shipped with Jboss Enterprise Application Platform 7.2 would accept an xinclude parameter in SAMLresponse XML. An att…

Mitigation only
Fix from $2,300 2019-06-12
Jboss Enterprise Application Platform MEDIUM 5.4
CVE-2019-3872

It was found that a SAMLRequest containing a script could be processed by Picketlink versions shipped in Jboss Application Platform 7.2.x and 7.1.x. …

Mitigation only
Fix from $1,600 2019-06-12
Jboss Enterprise Application Platform MEDIUM 5.4
CVE-2018-10934

A cross-site scripting (XSS) vulnerability was found in the JBoss Management Console versions before 7.1.6.CR1, 7.1.6.GA. Users with roles that can c…

Mitigation only
Fix from $1,600 2019-03-27
Satellite MEDIUM 5.4
CVE-2018-16887

A cross-site scripting (XSS) flaw was found in the katello component of Satellite. An attacker with privilege to create/edit organizations and locati…

Fix: 3.9.0+
Fix from $1,600 2019-01-13
Bodhi MEDIUM 6.1
CVE-2017-1002152

Bodhi 2.9.0 and lower is vulnerable to cross-site scripting resulting in code injection caused by incorrect validation of bug titles.

Fix: after 2.9.0
Fix from $1,600 2019-01-10
Keycloak MEDIUM 5.4
CVE-2018-14655

A flaw was found in Keycloak 3.4.3.Final, 4.0.0.Beta2, 4.3.0.Final. When using 'response_mode=form_post' it is possible to inject arbitrary Javascrip…

Mitigation only
Fix from $1,600 2018-11-13
Jboss Bpm Suite MEDIUM 5.4
CVE-2016-6343

JBoss BPM Suite 6 is vulnerable to a reflected XSS via dashbuilder. Remote attackers can entice authenticated users that have privileges to access da…

Fix: 6.4.2+
Fix from $1,600 2018-10-31
Openshift Container Platform MEDIUM 5.4
CVE-2018-10937

A cross site scripting flaw exists in the tetonic-console component of Openshift Container Platform 3.11. An attacker with the ability to create pods…

Patch available
Fix from $1,600 2018-09-11
Jboss Bpm Suite MEDIUM 5.4
CVE-2016-8608

JBoss BRMS 6 and BPM Suite 6 are vulnerable to a stored XSS via business process editor. The flaw is due to an incomplete fix for CVE-2016-5398. Remo…

Mitigation only
Fix from $1,600 2018-08-01
Satellite MEDIUM 5.4
CVE-2016-8639

It was found that foreman before 1.13.0 is vulnerable to a stored XSS via an organization or location name. This could allow an attacker with privile…

Fix: 1.13.0+
Fix from $1,600 2018-08-01
Satellite MEDIUM 5.4
CVE-2017-7514

A cross-site scripting (XSS) flaw was found in how the failed action entry is processed in Red Hat Satellite before version 5.8.0. A user able to spe…

Fix: 5.8.0+
Fix from $1,600 2018-07-30
Jboss Bpm Suite MEDIUM 6.1
CVE-2017-7463

JBoss BRMS 6 and BPM Suite 6 before 6.4.3 are vulnerable to a reflected XSS via artifact upload. A malformed XML file, if uploaded, causes an error m…

Fix: 6.4.3+
Fix from $1,600 2018-07-27
Jboss Bpm Suite MEDIUM 5.4
CVE-2017-2674

JBoss BRMS 6 and BPM Suite 6 before 6.4.3 are vulnerable to a stored XSS via several lists in Business Central. The flaw is due to lack of sanitation…

Fix: 6.4.3+
Fix from $1,600 2018-07-27
Cloudforms Management Engine MEDIUM 5.4
CVE-2017-15125

A flaw was found in CloudForms before 5.9.0.22 in the self-service UI snapshot feature where the name field is not properly sanitized for HTML and Ja…

Fix: 5.9.0.22+
Fix from $1,600 2018-07-27
Satellite MEDIUM 5.4
CVE-2017-12175

Red Hat Satellite before 6.5 is vulnerable to a XSS in discovery rule when you are entering filter and you use autocomplete functionality.

Fix: 6.5+
Fix from $1,600 2018-07-26
Satellite MEDIUM 5.4
CVE-2017-7538

A cross-site scripting (XSS) flaw was found in how an organization name is displayed in Satellite 5, before 5.8. A user able to change an organizatio…

Fix: 5.8+
Fix from $1,600 2018-07-26
Enterprise Linux Desktop MEDIUM 5.4
CVE-2017-7823

The content security policy (CSP) "sandbox" directive did not create a unique origin for the document, causing it to behave as if the "allow-same-ori…

Fix: 52.4.0 / 56.0+
Fix from $1,600 2018-06-11
Enterprise Linux MEDIUM 6.1
CVE-2017-5466

If a page is loaded from an original site through a hyperlink and contains a redirect to a "data:text/html" URL, triggering a reload will run the rel…

Fix: 52.1.0 / 53.0+
Fix from $1,600 2018-06-11
Cloudforms MEDIUM 6.1
CVE-2018-11627

Sinatra before 2.0.2 has XSS via the 400 Bad Request page that occurs upon a params parser exception.

Fix: 2.0.2+
Fix from $1,600 2018-05-31
Openshift MEDIUM 5.4
CVE-2017-7534

OpenShift Enterprise version 3.x is vulnerable to a stored XSS via the log viewer for pods. The flaw is due to lack of sanitation of user input, spec…

Mitigation only
Fix from $1,600 2018-04-11
Jbpm MEDIUM 5.4
CVE-2013-6465

Multiple cross-site scripting (XSS) vulnerabilities in JBPM KIE Workbench 6.0.x allow remote authenticated users to inject arbitrary web script or HT…

Patch available
Fix from $1,600 2017-12-19
Satellite MEDIUM 6.1
CVE-2017-15100

An attacker submitting facts to the Foreman server containing HTML can cause a stored XSS on certain pages: (1) Facts page, when clicking on the "cha…

Fix: 1.16.0+
Fix from $1,600 2017-11-27
Single Sign On MEDIUM 5.4
CVE-2017-12158

It was found that Keycloak would accept a HOST header URL in the admin console and use it to determine web resource locations. An attacker could use …

Mitigation only
Fix from $1,600 2017-10-26
Subscription Asset Manager MEDIUM 6.1
CVE-2014-0029

Multiple cross-site scripting (XSS) vulnerabilities in the SAM web application in Red Hat katello-headpin allow remote attackers to inject arbitrary …

Mitigation only
Fix from $1,600 2017-10-16
Mobile Application Platform MEDIUM 6.1
CVE-2017-7554

It was found that the App Studio component of RHMAP 4.4 executes javascript provided by a user. An attacker could use this flaw to execute a stored X…

Patch available
Fix from $1,600 2017-09-29
Jboss A Mq MEDIUM 5.4
CVE-2015-5181

The JBoss console in A-MQ allows remote attackers to execute arbitrary JavaScript.

Fix: after 6.0
Fix from $1,600 2017-09-25
Satellite MEDIUM 6.1
CVE-2014-0141

Cross-site scripting (XSS) vulnerability in Red Hat Satellite 6.0.3.

No fix yet
Fix from $1,600 2017-08-28
Ovirt Engine MEDIUM 6.1
CVE-2016-3113

Cross-site scripting (XSS) vulnerability in ovirt-engine allows remote attackers to inject arbitrary web script or HTML.

Mitigation only
Fix from $1,600 2017-08-07
Openstack MEDIUM 5.4
CVE-2016-6519

Cross-site scripting (XSS) vulnerability in the "Shares" overview in Openstack Manila before 2.5.1 allows remote authenticated users to inject arbitr…

Fix: after 2.5
Fix from $1,600 2017-04-21
Resteasy MEDIUM 6.1
CVE-2016-6347

Cross-site scripting (XSS) vulnerability in the default exception handler in RESTEasy allows remote attackers to inject arbitrary web script or HTML …

Mitigation only
Fix from $1,600 2017-04-20