Not a member of Pastebin yet?
Sign Up,
it unlocks many cool features!
- CVE-2017-16789: XSS Vulnerability Details
- ==========================================
- [Vulnerability description]
- Cross-site scripting (XSS) vulnerability in Integration Matters nJAMS 3, as used in TIBCO BusinessWorks Process Monitor through 3.0.1.3 and other products, allows remote authenticated administrators to inject arbitrary web script or HTML via unspecified vectors.
- ------------------------------------------
- [Vulnerability Type]
- Cross Site Scripting (XSS)
- ------------------------------------------
- [Vendor of Product]
- Integration Matters
- ------------------------------------------
- [Affected Product Code Base]
- nJAMS - 3
- TIBCO BWPM - 3.0.1.3
- ------------------------------------------
- [Attack Type]
- Remote
- ------------------------------------------
- [Impact Code execution]
- true
- ------------------------------------------
- [Attack Vectors]
- An authenticated administrator can inject arbitrary JavaScript or HTML code in the users' management panel of the web interface. The malicious code will be triggered when the page is visited by another administrator.
- Cristhian
Add Comment
Please, Sign In to add comment