Low severity2.6NVD Advisory· Published Jul 27, 2018· Updated Jun 17, 2026
CVE-2017-2658
CVE-2017-2658
Description
It was discovered that the Dashbuilder login page as used in Red Hat JBoss BPM Suite before 6.4.2 and Red Hat JBoss Data Virtualization & Services before 6.4.3 could be opened in an IFRAME, which made it possible to intercept and manipulate requests. An attacker could use this flaw to trick a user into performing arbitrary actions in the Console (clickjacking).
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
4- cpe:2.3:a:redhat:jboss_data_virtualization_\&_services:*:*:*:*:*:*:*:*Range: <6.4.3
- Red Hat/BPMSv5Range: 6.4.2
- Red Hat/JDVv5Range: 6.4.3
Patches
Vulnerability mechanics
References
4- rhn.redhat.com/errata/RHSA-2017-0557.htmlnvdBroken LinkVendor Advisory
- www.securityfocus.com/bid/97025nvdThird Party AdvisoryVDB Entry
- access.redhat.com/errata/RHSA-2018:2243nvdVendor Advisory
- bugzilla.redhat.com/show_bug.cginvdIssue TrackingVendor Advisory
News mentions
0No linked articles in our index yet.