Vulnerability index

Browse CVEs

104 matching
Filters 2 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Cross-site Scripting (XSS)CWE-79 × clear
CRITICAL 9.0 CVE-2019-3873 It was found that Picketlink as shipped with Jboss Enterprise Application Platform 7.2 would accept an xinclude parameter in SAMLresponse XML. An att… Jboss Enterprise Application Platform Mitigation only Fix from $2,3002019-06-12 MEDIUM 5.4 CVE-2019-3872 It was found that a SAMLRequest containing a script could be processed by Picketlink versions shipped in Jboss Application Platform 7.2.x and 7.1.x. … Jboss Enterprise Application Platform Mitigation only Fix from $1,6002019-06-12 MEDIUM 5.4 CVE-2018-10934 A cross-site scripting (XSS) vulnerability was found in the JBoss Management Console versions before 7.1.6.CR1, 7.1.6.GA. Users with roles that can c… Jboss Enterprise Application Platform Mitigation only Fix from $1,6002019-03-27 MEDIUM 5.4 CVE-2018-16887 A cross-site scripting (XSS) flaw was found in the katello component of Satellite. An attacker with privilege to create/edit organizations and locati… Satellite 3.9.0+ Fix from $1,6002019-01-13 MEDIUM 6.1 CVE-2017-1002152 Bodhi 2.9.0 and lower is vulnerable to cross-site scripting resulting in code injection caused by incorrect validation of bug titles. Bodhi after 2.9.0 Fix from $1,6002019-01-10 MEDIUM 5.4 CVE-2018-14655 A flaw was found in Keycloak 3.4.3.Final, 4.0.0.Beta2, 4.3.0.Final. When using 'response_mode=form_post' it is possible to inject arbitrary Javascrip… Keycloak Mitigation only Fix from $1,6002018-11-13 MEDIUM 5.4 CVE-2016-6343 JBoss BPM Suite 6 is vulnerable to a reflected XSS via dashbuilder. Remote attackers can entice authenticated users that have privileges to access da… Jboss Bpm Suite 6.4.2+ Fix from $1,6002018-10-31 MEDIUM 5.4 CVE-2018-10937 A cross site scripting flaw exists in the tetonic-console component of Openshift Container Platform 3.11. An attacker with the ability to create pods… Openshift Container Platform Patch available Fix from $1,6002018-09-11 MEDIUM 5.4 CVE-2016-8608 JBoss BRMS 6 and BPM Suite 6 are vulnerable to a stored XSS via business process editor. The flaw is due to an incomplete fix for CVE-2016-5398. Remo… Jboss Bpm Suite Mitigation only Fix from $1,6002018-08-01 MEDIUM 5.4 CVE-2016-8639 It was found that foreman before 1.13.0 is vulnerable to a stored XSS via an organization or location name. This could allow an attacker with privile… Satellite 1.13.0+ Fix from $1,6002018-08-01 MEDIUM 5.4 CVE-2017-7514 A cross-site scripting (XSS) flaw was found in how the failed action entry is processed in Red Hat Satellite before version 5.8.0. A user able to spe… Satellite 5.8.0+ Fix from $1,6002018-07-30 MEDIUM 6.1 CVE-2017-7463 JBoss BRMS 6 and BPM Suite 6 before 6.4.3 are vulnerable to a reflected XSS via artifact upload. A malformed XML file, if uploaded, causes an error m… Jboss Bpm Suite 6.4.3+ Fix from $1,6002018-07-27 MEDIUM 5.4 CVE-2017-2674 JBoss BRMS 6 and BPM Suite 6 before 6.4.3 are vulnerable to a stored XSS via several lists in Business Central. The flaw is due to lack of sanitation… Jboss Bpm Suite 6.4.3+ Fix from $1,6002018-07-27 MEDIUM 5.4 CVE-2017-15125 A flaw was found in CloudForms before 5.9.0.22 in the self-service UI snapshot feature where the name field is not properly sanitized for HTML and Ja… Cloudforms Management Engine 5.9.0.22+ Fix from $1,6002018-07-27 MEDIUM 5.4 CVE-2017-12175 Red Hat Satellite before 6.5 is vulnerable to a XSS in discovery rule when you are entering filter and you use autocomplete functionality. Satellite 6.5+ Fix from $1,6002018-07-26 MEDIUM 5.4 CVE-2017-7538 A cross-site scripting (XSS) flaw was found in how an organization name is displayed in Satellite 5, before 5.8. A user able to change an organizatio… Satellite 5.8+ Fix from $1,6002018-07-26 MEDIUM 5.4 CVE-2017-7823 The content security policy (CSP) "sandbox" directive did not create a unique origin for the document, causing it to behave as if the "allow-same-ori… Enterprise Linux Desktop 52.4.0 / 56.0+ Fix from $1,6002018-06-11 MEDIUM 6.1 CVE-2017-5466 If a page is loaded from an original site through a hyperlink and contains a redirect to a "data:text/html" URL, triggering a reload will run the rel… Enterprise Linux 52.1.0 / 53.0+ Fix from $1,6002018-06-11 MEDIUM 6.1 CVE-2018-11627 Sinatra before 2.0.2 has XSS via the 400 Bad Request page that occurs upon a params parser exception. Cloudforms 2.0.2+ Fix from $1,6002018-05-31 MEDIUM 5.4 CVE-2017-7534 OpenShift Enterprise version 3.x is vulnerable to a stored XSS via the log viewer for pods. The flaw is due to lack of sanitation of user input, spec… Openshift Mitigation only Fix from $1,6002018-04-11 MEDIUM 5.4 CVE-2013-6465 Multiple cross-site scripting (XSS) vulnerabilities in JBPM KIE Workbench 6.0.x allow remote authenticated users to inject arbitrary web script or HT… Jbpm Patch available Fix from $1,6002017-12-19 MEDIUM 6.1 CVE-2017-15100 An attacker submitting facts to the Foreman server containing HTML can cause a stored XSS on certain pages: (1) Facts page, when clicking on the "cha… Satellite 1.16.0+ Fix from $1,6002017-11-27 MEDIUM 5.4 CVE-2017-12158 It was found that Keycloak would accept a HOST header URL in the admin console and use it to determine web resource locations. An attacker could use … Single Sign On Mitigation only Fix from $1,6002017-10-26 MEDIUM 6.1 CVE-2014-0029 Multiple cross-site scripting (XSS) vulnerabilities in the SAM web application in Red Hat katello-headpin allow remote attackers to inject arbitrary … Subscription Asset Manager Mitigation only Fix from $1,6002017-10-16 MEDIUM 6.1 CVE-2017-7554 It was found that the App Studio component of RHMAP 4.4 executes javascript provided by a user. An attacker could use this flaw to execute a stored X… Mobile Application Platform Patch available Fix from $1,6002017-09-29 MEDIUM 5.4 CVE-2015-5181 The JBoss console in A-MQ allows remote attackers to execute arbitrary JavaScript. Jboss A Mq after 6.0 Fix from $1,6002017-09-25 MEDIUM 6.1 CVE-2014-0141 Cross-site scripting (XSS) vulnerability in Red Hat Satellite 6.0.3. Satellite No fix yet Fix from $1,6002017-08-28 MEDIUM 6.1 CVE-2016-3113 Cross-site scripting (XSS) vulnerability in ovirt-engine allows remote attackers to inject arbitrary web script or HTML. Ovirt Engine Mitigation only Fix from $1,6002017-08-07 MEDIUM 5.4 CVE-2016-6519 Cross-site scripting (XSS) vulnerability in the "Shares" overview in Openstack Manila before 2.5.1 allows remote authenticated users to inject arbitr… Openstack after 2.5 Fix from $1,6002017-04-21 MEDIUM 6.1 CVE-2016-6347 Cross-site scripting (XSS) vulnerability in the default exception handler in RESTEasy allows remote attackers to inject arbitrary web script or HTML … Resteasy Mitigation only Fix from $1,6002017-04-20