CVE-2016-8608: Red Hat JBoss Bpm Suite

Medium severity, CVSS 5.4. EPSS: 1.3% chance of exploitation in the next 30 days.

JBoss BRMS 6 and BPM Suite 6 are vulnerable to a stored XSS via business process editor. The flaw is due to an incomplete fix for CVE-2016-5398. Remote, authenticated attackers that have privileges to create business processes can store scripts in them, which are not properly sanitized before showing to other users, including admins.

Affected products

  • Red Hat JBoss Bpm Suite: version 6.0.0 only
  • Red Hat JBoss Business Rules Management System: version 6.0.0 only

Published 2018-08-01. Last modified 2026-06-17.