VDB
RHSA-2013:1286
RHSA-2013:1286
PUBLISHED
CVSS 4.300000190734863 MEDIUM
Multiple cross-site scripting (XSS) vulnerabilities in Fuse Management Console in Red Hat JBoss Fuse 6.0.0 before patch 3 and JBoss A-MQ 6.0.0 before patch 3 allow remote attackers to inject arbitrary web script or HTML via the (1) user field in the create user page or (2) profile version to the create profile page.
Risk Scores
CVSS 2.0
4.300000190734863
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Red Hat | Red Hat JBoss Fuse 6.0 | |
| Red Hat | Red Hat JBoss A-MQ 6.0 |
Timeline
- Sep 26, 2013 CVE Published
- Nov 21, 2025 CVE Updated
- Apr 29, 2026 Distribution Patch
- Apr 29, 2026 Distribution Patch
- Apr 29, 2026 Security Advisory
- Apr 29, 2026 Security Advisory
References
- https://access.redhat.com/errata/RHSA-2013:1286 advisory
- https://access.redhat.com/security/updates/classification/#moderate advisory
- https://access.redhat.com/jbossnetwork/restricted/listSoftware.html?product=jboss.fuse&downloadType=securityPatches&version=6.0.0 advisory
- https://access.redhat.com/jbossnetwork/restricted/listSoftware.html?product=jboss.amq&downloadType=securityPatches&version=6.0.0 advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=1011736 issue
- https://security.access.redhat.com/data/csaf/v2/advisories/2013/rhsa-2013_1286.json advisory
- https://access.redhat.com/security/cve/CVE-2013-4372 advisory
- https://www.cve.org/CVERecord?id=CVE-2013-4372 advisory
- https://nvd.nist.gov/vuln/detail/CVE-2013-4372 advisory