Release date: 2011-12-16
Updated on: 2011-12-19
Affected Systems:
RedHat JBoss Operations Network 2.4.1
Unaffected system:
RedHat JBoss Operations Network 3.0
Description:
--------------------------------------------------------------------------------
Bugtraq id: 51095
Cve id: CVE-2011-3206
JBoss Operations Network is an open source Network management software based on Java EE.
JBoss Operations Network has multiple cross-site scripting vulnerabilities in the implementation of the JON management interface. Remote attackers can trick users into browsing specially crafted URLs to execute cross-site scripting attacks, steal Cookie authentication creden.
<* Source: vendor
Link: https://bugzilla.redhat.com/show_bug.cgi? Id = 734662
Http://secunia.com/advisories/47280/
*>
Suggestion:
--------------------------------------------------------------------------------
Vendor patch:
RedHat
------
The vendor has released a patch to fix this security problem. Please download it from the vendor's homepage:
Http://www.redhat.com/apps/support/errata/index.html