Release date:
Updated on:
Affected Systems:
JBoss Group JBoss Enterprise Web Platform for RHEL 5 Server 5
JBoss Group JBoss Enterprise Web Platform for RHEL 4ES 5
JBoss Group JBoss Enterprise Web Platform for RHEL 4AS 5
Description:
--------------------------------------------------------------------------------
Bugtraq id: 57548
CVE (CAN) ID: CVE-2011-4575
JBoss Enterprise Application Platform (EAP) is a middleware Platform for J2EE applications.
JBoss Enterprise Application Platform has an XSS vulnerability in implementation, which allows remote attackers to perform XSS attacks against victims using the JMX Console.
<* Source: Taylor Krpata
Link: http://rhn.redhat.com/errata/RHSA-2013-0194.html
*>
Suggestion:
--------------------------------------------------------------------------------
Vendor patch:
JBoss Group
-----------
The vendor has released a patch to fix this security problem. Please download it from the vendor's homepage:
Http://www.jboss.org/