Lucene search

K
mskbMicrosoftKB5009301
HistoryDec 14, 2021 - 8:00 a.m.

KB5009301 - FIX: XSS attacks and open redirect vulnerability in the ESB.Portal sample application for Microsoft BizTalk ESB Toolkit

2021-12-1408:00:00
Microsoft
support.microsoft.com
14

4.3 Medium

CVSS2

Attack Vector

NETWORK

Attack Complexity

MEDIUM

Authentication

NONE

Confidentiality Impact

PARTIAL

Integrity Impact

NONE

Availability Impact

NONE

AV:N/AC:M/Au:N/C:P/I:N/A:N

7.4 High

CVSS3

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

REQUIRED

Scope

CHANGED

Confidentiality Impact

HIGH

Integrity Impact

NONE

Availability Impact

NONE

CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:N/A:N

7.3 High

AI Score

Confidence

High

0.004 Low

EPSS

Percentile

72.1%

KB5009301 - FIX: XSS attacks and open redirect vulnerability in the ESB.Portal sample application for Microsoft BizTalk ESB Toolkit

Symptoms

If you use the ESB.Portal sample application that’s shipped as part of the Microsoft BizTalk ESB Toolkit, you might be vulnerable to a cross-site scripting (XSS) attack. For more information, see the following Common Vulnerabilities and Exposures (CVE) advisory:

Status

Microsoft has confirmed that this is a problem in the Microsoft products that are listed in the “Applies to” section.

Resolution

To fix this problem, download and install the update for Microsoft BizTalk ESB Toolkit.

**Note:**This installation will update the ESBSource.zip file that’s present in the ESB Toolkit installation folder. You will have to manually apply the fix to your running ESB.Portal application.

References

For information about the service packs and cumulative update list for BizTalk Server, see the following Microsoft Knowledge Base article:

4.3 Medium

CVSS2

Attack Vector

NETWORK

Attack Complexity

MEDIUM

Authentication

NONE

Confidentiality Impact

PARTIAL

Integrity Impact

NONE

Availability Impact

NONE

AV:N/AC:M/Au:N/C:P/I:N/A:N

7.4 High

CVSS3

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

REQUIRED

Scope

CHANGED

Confidentiality Impact

HIGH

Integrity Impact

NONE

Availability Impact

NONE

CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:N/A:N

7.3 High

AI Score

Confidence

High

0.004 Low

EPSS

Percentile

72.1%