LOW · 2.6

CVE-2017-2658

It was discovered that the Dashbuilder login page as used in Red Hat JBoss BPM Suite before 6.4.2 and Red Hat JBoss Data Virtualization & Services before 6.4.3 could be opened in an IFRAME, which made...

Vulnerability Description

It was discovered that the Dashbuilder login page as used in Red Hat JBoss BPM Suite before 6.4.2 and Red Hat JBoss Data Virtualization & Services before 6.4.3 could be opened in an IFRAME, which made it possible to intercept and manipulate requests. An attacker could use this flaw to trick a user into performing arbitrary actions in the Console (clickjacking).

CVSS Score

2.6

LOW

CVSS:3.0/AV:A/AC:H/PR:N/UI:R/S:U/C:N/I:L/A:N
Attack Vector
ADJACENT_NETWORK
Attack Complexity
HIGH
Privileges Required
NONE
User Interaction
REQUIRED
Scope
UNCHANGED
Confidentiality
NONE
Integrity
LOW
Availability
NONE

Affected Products

VendorProductVersions
RedhatJboss Bpm Suite< 6.4.2
RedhatJboss Data Virtualization \& Services< 6.4.3

Related Weaknesses (CWE)

References

FAQ

What is CVE-2017-2658?

CVE-2017-2658 is a vulnerability with a CVSS score of 2.6 (LOW). It was discovered that the Dashbuilder login page as used in Red Hat JBoss BPM Suite before 6.4.2 and Red Hat JBoss Data Virtualization & Services before 6.4.3 could be opened in an IFRAME, which made...

How severe is CVE-2017-2658?

CVE-2017-2658 has been rated LOW with a CVSS base score of 2.6/10. Review the CVSS metrics above for detailed severity breakdown.

Is there a patch for CVE-2017-2658?

Check the references section above for vendor advisories and patch information. Affected products include: Redhat Jboss Bpm Suite, Redhat Jboss Data Virtualization \& Services.