CVE-2017-7463 is a reflected Cross-Site Scripting (XSS) vulnerability affecting Red Hat JBoss BRMS 6 and BPM Suite 6 before version 6.4.3. An attacker can exploit this by uploading a specially crafted XML file, causing an unfiltered error message containing malicious script to be displayed to a user. This allows for script execution within the victim's browser context, potentially leading to information disclosure or session hijacking. The vulnerability has a CVSS v3.0 score of 6.1 (Medium), indicating a low attack complexity and requiring user interaction, but can be exploited remotely over the network. The potential impact includes limited confidentiality and integrity compromise. There is no evidence of active exploitation, nor are there publicly available exploit modules in Metasploit, Nuclei, or ExploitDB. The vulnerability has received minimal community discussion and media coverage, suggesting a low level of public awareness or interest.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
>= 6.0.0, < 6.4.3CPE matchmatch criteria | cpe:2.3:a:redhat:jboss_bpm_suite:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.0
CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.1 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.