Vulnerability Description
The dashbuilder in Red Hat JBoss BPM Suite 6.3.2 does not properly handle CSRF tokens generated during an active session and includes them in query strings, which makes easier for remote attackers to (1) bypass CSRF protection mechanisms or (2) conduct cross-site request forgery (CSRF) attacks by obtaining an old token.
CVSS Score
HIGH
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Redhat | Jboss Bpm Suite | 6.3.2 |
Related Weaknesses (CWE)
References
- http://rhn.redhat.com/errata/RHSA-2017-0557.html
- http://www.securityfocus.com/bid/92760Third Party AdvisoryVDB Entry
- https://access.redhat.com/errata/RHSA-2018:0296
- https://bugzilla.redhat.com/show_bug.cgi?id=1373347Issue Tracking
- http://rhn.redhat.com/errata/RHSA-2017-0557.html
- http://www.securityfocus.com/bid/92760Third Party AdvisoryVDB Entry
- https://access.redhat.com/errata/RHSA-2018:0296
- https://bugzilla.redhat.com/show_bug.cgi?id=1373347Issue Tracking
FAQ
What is CVE-2016-7034?
CVE-2016-7034 is a vulnerability with a CVSS score of 8.8 (HIGH). The dashbuilder in Red Hat JBoss BPM Suite 6.3.2 does not properly handle CSRF tokens generated during an active session and includes them in query strings, which makes easier for remote attackers to ...
How severe is CVE-2016-7034?
CVE-2016-7034 has been rated HIGH with a CVSS base score of 8.8/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2016-7034?
Check the references section above for vendor advisories and patch information. Affected products include: Redhat Jboss Bpm Suite.