Multiple cross-site scripting (XSS) vulnerabilities in Fuse Management Console in Red Hat JBoss Fuse 6.0.0 before patch 3 and JBoss A-MQ 6.0.0 before patch 3 allow remote attackers to inject arbitrary web script or HTML via the (1) user field in the create user page or (2) profile version to the create profile page.
CPE | Name | Operator | Version |
---|---|---|---|
jboss_a-mq | eq | 6.0.0 | |
jboss_fuse | eq | 6.0.0 |
fusesource.com/forge/git/fuseenterprise.git/?p=fuseenterprise.git%3Ba=commitdiff%3Bh=f5436ea1c5547c851bb6f92561272fe42c146e68
fusesource.com/issues/browse/FMC-495
rhn.redhat.com/errata/RHSA-2013-1286.html
rhn.redhat.com/errata/RHSA-2013-1862.html
www.securityfocus.com/bid/62659
bugzilla.redhat.com/show_bug.cgi?id=1011736
github.com/jboss-fuse/fuse/commit/e280cb370323eeb759030919d5111ed809e8ded5