Show plain JSON{"acknowledgement": "Red Hat would like to thank Tomas Rzepka for reporting this issue.", "affected_release": [{"advisory": "RHSA-2017:2674", "cpe": "cpe:/a:redhat:mobile_application_platform:4.5", "package": "fh-system-dump-tool-0:1.0.0-5.el7", "product_name": "Red Hat Mobile Application Platform 4.5", "release_date": "2017-09-18T00:00:00Z"}, {"advisory": "RHSA-2017:2674", "cpe": "cpe:/a:redhat:mobile_application_platform:4.5", "package": "fping-0:3.10-4.el7map", "product_name": "Red Hat Mobile Application Platform 4.5", "release_date": "2017-09-18T00:00:00Z"}, {"advisory": "RHSA-2017:2674", "cpe": "cpe:/a:redhat:mobile_application_platform:4.5", "package": "nagios-0:4.0.8-8.el7map", "product_name": "Red Hat Mobile Application Platform 4.5", "release_date": "2017-09-18T00:00:00Z"}, {"advisory": "RHSA-2017:2674", "cpe": "cpe:/a:redhat:mobile_application_platform:4.5", "package": "nagios-plugins-0:2.0.3-3.el7map", "product_name": "Red Hat Mobile Application Platform 4.5", "release_date": "2017-09-18T00:00:00Z"}, {"advisory": "RHSA-2017:2674", "cpe": "cpe:/a:redhat:mobile_application_platform:4.5", "package": "perl-Crypt-CBC-0:2.33-2.el7map", "product_name": "Red Hat Mobile Application Platform 4.5", "release_date": "2017-09-18T00:00:00Z"}, {"advisory": "RHSA-2017:2674", "cpe": "cpe:/a:redhat:mobile_application_platform:4.5", "package": "perl-Crypt-DES-0:2.05-20.el7map", "product_name": "Red Hat Mobile Application Platform 4.5", "release_date": "2017-09-18T00:00:00Z"}, {"advisory": "RHSA-2017:2674", "cpe": "cpe:/a:redhat:mobile_application_platform:4.5", "package": "perl-Net-SNMP-0:6.0.1-7.el7map", "product_name": "Red Hat Mobile Application Platform 4.5", "release_date": "2017-09-18T00:00:00Z"}, {"advisory": "RHSA-2017:2674", "cpe": "cpe:/a:redhat:mobile_application_platform:4.5", "package": "phantomjs-0:1.9.7-3.el7map", "product_name": "Red Hat Mobile Application Platform 4.5", "release_date": "2017-09-18T00:00:00Z"}, {"advisory": "RHSA-2017:2674", "cpe": "cpe:/a:redhat:mobile_application_platform:4.5", "package": "python-meld3-0:0.6.10-1.el7map", "product_name": "Red Hat Mobile Application Platform 4.5", "release_date": "2017-09-18T00:00:00Z"}, {"advisory": "RHSA-2017:2674", "cpe": "cpe:/a:redhat:mobile_application_platform:4.5", "package": "qstat-0:2.11-13.20080912svn311.el7map", "product_name": "Red Hat Mobile Application Platform 4.5", "release_date": "2017-09-18T00:00:00Z"}, {"advisory": "RHSA-2017:2674", "cpe": "cpe:/a:redhat:mobile_application_platform:4.5", "package": "radiusclient-ng-0:0.5.6-9.el7map", "product_name": "Red Hat Mobile Application Platform 4.5", "release_date": "2017-09-18T00:00:00Z"}, {"advisory": "RHSA-2017:2674", "cpe": "cpe:/a:redhat:mobile_application_platform:4.5", "package": "redis-0:2.8.21-2.el7map", "product_name": "Red Hat Mobile Application Platform 4.5", "release_date": "2017-09-18T00:00:00Z"}, {"advisory": "RHSA-2017:2674", "cpe": "cpe:/a:redhat:mobile_application_platform:4.5", "package": "rhmap-fh-openshift-templates-0:4.5.0-11.el7", "product_name": "Red Hat Mobile Application Platform 4.5", "release_date": "2017-09-18T00:00:00Z"}, {"advisory": "RHSA-2017:2674", "cpe": "cpe:/a:redhat:mobile_application_platform:4.5", "package": "rhmap-mod_authnz_external-0:3.3.1-7.el7map", "product_name": "Red Hat Mobile Application Platform 4.5", "release_date": "2017-09-18T00:00:00Z"}, {"advisory": "RHSA-2017:2674", "cpe": "cpe:/a:redhat:mobile_application_platform:4.5", "package": "sendEmail-0:1.56-2.el7", "product_name": "Red Hat Mobile Application Platform 4.5", "release_date": "2017-09-18T00:00:00Z"}, {"advisory": "RHSA-2017:2674", "cpe": "cpe:/a:redhat:mobile_application_platform:4.5", "package": "ssmtp-0:2.64-14.el7map", "product_name": "Red Hat Mobile Application Platform 4.5", "release_date": "2017-09-18T00:00:00Z"}, {"advisory": "RHSA-2017:2674", "cpe": "cpe:/a:redhat:mobile_application_platform:4.5", "package": "supervisor-0:3.1.3-3.el7map", "product_name": "Red Hat Mobile Application Platform 4.5", "release_date": "2017-09-18T00:00:00Z"}, {"advisory": "RHSA-2017:2675", "cpe": "cpe:/a:redhat:mobile_application_platform:4.5", "package": "rhmap45/fh-aaa:1.0.5-12", "product_name": "Red Hat Mobile Application Platform 4.5", "release_date": "2017-09-18T00:00:00Z"}], "bugzilla": {"description": "RHMAP: Stored XSS in App Store", "id": "1478770", "url": "https://bugzilla.redhat.com/show_bug.cgi?id=1478770"}, "csaw": false, "cvss3": {"cvss3_base_score": "6.1", "cvss3_scoring_vector": "CVSS:3.0/AV:N/AC:H/PR:N/UI:R/S:C/C:H/I:N/A:N", "status": "verified"}, "details": ["It was found that the App Studio component of RHMAP 4.4 executes javascript provided by a user. An attacker could use this flaw to execute a stored XSS attack on an application administrator using App Studio.", "A flaw was found where the App Studio component of RHMAP 4.4 executes javascript provided by a user. An attacker could use this flaw to execute a stored XSS attack on an application administrator using App Studio."], "name": "CVE-2017-7554", "public_date": "2017-09-11T00:00:00Z", "references": ["https://www.cve.org/CVERecord?id=CVE-2017-7554\nhttps://nvd.nist.gov/vuln/detail/CVE-2017-7554"], "threat_severity": "Moderate"}