PT-2017-13810 · Wso2 · Wso2 Data Services Server+7
Published
2017-10-03
·
Updated
2017-10-23
·
CVE-2017-14995
CVSS v3.1
6.1
Medium
| Vector | AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N |
Name of the Vulnerable Software and Affected Versions
WSO2 Application Server version 5.3.0
WSO2 Business Process Server version 3.6.0
WSO2 Business Rules Server version 2.2.0
WSO2 Complex Event Processor version 4.2.0
WSO2 Dashboard Server version 2.0.0
WSO2 Data Analytics Server version 3.1.0
WSO2 Data Services Server version 3.5.1
WSO2 Machine Learner version 1.2.0
Description
The Management Console in the listed WSO2 products is affected by a stored XSS issue. This means that an attacker could potentially inject malicious code into the console, which would then be executed by the application.
Recommendations
For WSO2 Application Server version 5.3.0, update to a version that includes a fix for the stored XSS issue in the Management Console.
For WSO2 Business Process Server version 3.6.0, update to a version that includes a fix for the stored XSS issue in the Management Console.
For WSO2 Business Rules Server version 2.2.0, update to a version that includes a fix for the stored XSS issue in the Management Console.
For WSO2 Complex Event Processor version 4.2.0, update to a version that includes a fix for the stored XSS issue in the Management Console.
For WSO2 Dashboard Server version 2.0.0, update to a version that includes a fix for the stored XSS issue in the Management Console.
For WSO2 Data Analytics Server version 3.1.0, update to a version that includes a fix for the stored XSS issue in the Management Console.
For WSO2 Data Services Server version 3.5.1, update to a version that includes a fix for the stored XSS issue in the Management Console.
For WSO2 Machine Learner version 1.2.0, update to a version that includes a fix for the stored XSS issue in the Management Console.
Fix
XSS
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Wso2 Application Server
Wso2 Business Process Server
Wso2 Business Rules Server
Wso2 Complex Event Processor
Wso2 Dashboard Server
Wso2 Data Analytics Server
Wso2 Data Services Server
Wso2 Machine Learner