Release date: 2011-12-02
Updated on: 2011-12-05
Affected Systems:
JBoss Group JBoss Application Server 7.x
Description:
--------------------------------------------------------------------------------
Bugtraq id: 50888
Cve id: CVE-2011-3609
Jboss is a very popular open-source J2EE application server.
The Jboss implementation has the input verification vulnerability. Some inputs passed to the message center through the console are not properly filtered before being returned to the user, attackers can execute arbitrary HTML and script code in the user's browser.
<* Source: David Black
Link: https://bugzilla.redhat.com/show_bug.cgi? Id = 743006
*>
Suggestion:
--------------------------------------------------------------------------------
Vendor patch:
JBoss Group
-----------
The vendor has released a patch to fix this security problem. Please download it from the vendor's homepage:
Http://www.jboss.org/