VYPR
Medium severity6.1NVD Advisory· Published Jul 27, 2018· Updated Jun 17, 2026

CVE-2017-7463

CVE-2017-7463

Description

JBoss BRMS 6 and BPM Suite 6 before 6.4.3 are vulnerable to a reflected XSS via artifact upload. A malformed XML file, if uploaded, causes an error message to appear that includes part of the bad XML code verbatim without filtering out scripts. Successful exploitation would allow execution of script code within the context of the affected user.

AI Insight

LLM-synthesized narrative grounded in this CVE's description and references.

Affected products

2
  • cpe:2.3:a:redhat:jboss_bpm_suite:*:*:*:*:*:*:*:*
    Range: >=6.0.0,<6.4.3
  • Red Hat/business-centralv5
    Range: 6.4.3

Patches

Vulnerability mechanics

References

4

News mentions

0

No linked articles in our index yet.