Medium severity6.1NVD Advisory· Published Jul 27, 2018· Updated Jun 17, 2026
CVE-2017-7463
CVE-2017-7463
Description
JBoss BRMS 6 and BPM Suite 6 before 6.4.3 are vulnerable to a reflected XSS via artifact upload. A malformed XML file, if uploaded, causes an error message to appear that includes part of the bad XML code verbatim without filtering out scripts. Successful exploitation would allow execution of script code within the context of the affected user.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
2- Red Hat/business-centralv5Range: 6.4.3
Patches
Vulnerability mechanics
References
4- www.securityfocus.com/bid/98385nvdThird Party AdvisoryVDB Entry
- access.redhat.com/errata/RHSA-2017:1217nvdBroken LinkVendor Advisory
- access.redhat.com/errata/RHSA-2017:1218nvdBroken LinkVendor Advisory
- bugzilla.redhat.com/show_bug.cginvdIssue TrackingVendor Advisory
News mentions
0No linked articles in our index yet.