SB20260925259 - Cross-site scripting in Java HTML Sanitizer
Published: September 25, 2026
Breakdown by Severity
- Low
- Medium
- High
- Critical
Description
This security bulletin contains information about 1 vulnerability.
1) Cross-site scripting (CVE-ID: N/A)
CWE-ID: CWE-79 - Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
CVSSv4: 5.1 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:N/VI:N/VA:N/SC:L/SI:L/SA:N]
The vulnerability allows a remote attacker to disclose sensitive information and modify web page content.
The vulnerability exists due to improper neutralization of input during web page generation in StylingPolicy URL handling when processing URLs in style attributes. A remote attacker can provide a URL containing quotes, backslashes, or control characters to disclose sensitive information and modify web page content.
User interaction is required.
Remediation
Install update from vendor's website.