Medium severity6.1NVD Advisory· Published Oct 31, 2018· Updated Jun 17, 2026
CVE-2016-6343
CVE-2016-6343
Description
JBoss BPM Suite 6 is vulnerable to a reflected XSS via dashbuilder. Remote attackers can entice authenticated users that have privileges to access dashbuilder (usually admins) to click on links to /dashbuilder/Controller containing malicious scripts. Successful exploitation would allow execution of script code within the context of the affected user.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
4cpe:2.3:a:redhat:jboss_bpm_suite:*:*:*:*:*:*:*:*+ 1 more
- cpe:2.3:a:redhat:jboss_bpm_suite:*:*:*:*:*:*:*:*range: >=6.0.0,<6.4.2
- (no CPE)range: 6
Patches
Vulnerability mechanics
References
4- rhn.redhat.com/errata/RHSA-2017-0557.htmlnvdBroken LinkVendor Advisory
- www.securityfocus.com/bid/96987nvdThird Party AdvisoryVDB Entry
- access.redhat.com/errata/RHSA-2018:0296nvdVendor Advisory
- bugzilla.redhat.com/show_bug.cginvdIssue Tracking
News mentions
0No linked articles in our index yet.