Vulnerabilities (CVE)

Filtered by vendor Redhat Subscribe
Filtered by product Jboss Bpm Suite
CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2016-7034 1 Redhat 1 Jboss Bpm Suite 2018-02-15 6.8 MEDIUM 8.8 HIGH
The dashbuilder in Red Hat JBoss BPM Suite 6.3.2 does not properly handle CSRF tokens generated during an active session and includes them in query strings, which makes easier for remote attackers to (1) bypass CSRF protection mechanisms or (2) conduct cross-site request forgery (CSRF) attacks by obtaining an old token.
CVE-2016-5401 1 Redhat 2 Jboss Bpm Suite, Jboss Enterprise Brms Platform 2017-04-26 6.8 MEDIUM 8.8 HIGH
Cross-site request forgery (CSRF) vulnerability in Red Hat JBoss BRMS and BPMS 6 allows remote attackers to hijack the authentication of users for requests that modify instances via a crafted web page.