CVE-2016-6344: Red Hat JBoss Bpm Suite

Medium severity, CVSS 5.3. EPSS: 2.2% chance of exploitation in the next 30 days.

Red Hat JBoss BPM Suite 6.3.x does not include the HTTPOnly flag in a Set-Cookie header for session cookies, which makes it easier for remote attackers to obtain potentially sensitive information via script access to the cookies.

Affected products

  • Red Hat JBoss Bpm Suite: version 6.3 only

Published 2016-09-07. Last modified 2026-06-17.