Lucene search

K
redhatRedHatRHSA-2014:1973
HistoryDec 09, 2014 - 5:53 p.m.

(RHSA-2014:1973) Moderate: Red Hat JBoss Portal 6.1.1 security update

2014-12-0917:53:43
access.redhat.com
19

EPSS

0.001

Percentile

49.1%

Red Hat JBoss Portal is the open source implementation of the Java EE suite
of services and Portal services running atop Red Hat JBoss Enterprise
Application Platform. It comprises a set of offerings for enterprise
customers who are looking for pre-configured profiles of JBoss Middleware
components that have been tested and certified together to provide an
integrated experience.

RichFaces is an open source framework that adds Ajax capability into
existing JavaServer Faces (JSF) applications.

It was found that RichFaces accepted arbitrary strings included in a URL
and returned them unencoded in a CSS file. A remote attacker could use this
flaw to perform cross-site scripting (XSS) attacks against a user running a
RichFaces application. (CVE-2014-7852)

All users of Red Hat JBoss Portal 6.1.1 as provided from the Red Hat
Customer Portal are advised to install this update.

EPSS

0.001

Percentile

49.1%

Related for RHSA-2014:1973