PT-2017-13810 · Wso2 · Wso2 Data Services Server+7

Published

2017-10-03

·

Updated

2017-10-23

·

CVE-2017-14995

CVSS v3.1

6.1

Medium

VectorAV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
Name of the Vulnerable Software and Affected Versions WSO2 Application Server version 5.3.0 WSO2 Business Process Server version 3.6.0 WSO2 Business Rules Server version 2.2.0 WSO2 Complex Event Processor version 4.2.0 WSO2 Dashboard Server version 2.0.0 WSO2 Data Analytics Server version 3.1.0 WSO2 Data Services Server version 3.5.1 WSO2 Machine Learner version 1.2.0
Description The Management Console in the listed WSO2 products is affected by a stored XSS issue. This means that an attacker could potentially inject malicious code into the console, which would then be executed by the application.
Recommendations For WSO2 Application Server version 5.3.0, update to a version that includes a fix for the stored XSS issue in the Management Console. For WSO2 Business Process Server version 3.6.0, update to a version that includes a fix for the stored XSS issue in the Management Console. For WSO2 Business Rules Server version 2.2.0, update to a version that includes a fix for the stored XSS issue in the Management Console. For WSO2 Complex Event Processor version 4.2.0, update to a version that includes a fix for the stored XSS issue in the Management Console. For WSO2 Dashboard Server version 2.0.0, update to a version that includes a fix for the stored XSS issue in the Management Console. For WSO2 Data Analytics Server version 3.1.0, update to a version that includes a fix for the stored XSS issue in the Management Console. For WSO2 Data Services Server version 3.5.1, update to a version that includes a fix for the stored XSS issue in the Management Console. For WSO2 Machine Learner version 1.2.0, update to a version that includes a fix for the stored XSS issue in the Management Console.

Fix

XSS

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2017-14995

Affected Products

Wso2 Application Server
Wso2 Business Process Server
Wso2 Business Rules Server
Wso2 Complex Event Processor
Wso2 Dashboard Server
Wso2 Data Analytics Server
Wso2 Data Services Server
Wso2 Machine Learner