Vulnerability Monitor

The vendors, products, and vulnerabilities you care about

CVE-2017-14995


The Management Console in WSO2 Application Server 5.3.0, WSO2 Business Process Server 3.6.0, WSO2 Business Rules Server 2.2.0, WSO2 Complex Event Processor 4.2.0, WSO2 Dashboard Server 2.0.0, WSO2 Data Analytics Server 3.1.0, WSO2 Data Services Server 3.5.1, and WSO2 Machine Learner 1.2.0 is affected by stored XSS.


Published

2017-10-04T01:29:03.277

Last Modified

2025-04-20T01:37:25.860

Status

Deferred

Source

[email protected]

Severity

CVSSv3.0: 6.1 (MEDIUM)

CVSSv2 Vector

AV:N/AC:M/Au:N/C:N/I:P/A:N

  • Access Vector: NETWORK
  • Access Complexity: MEDIUM
  • Authentication: NONE
  • Confidentiality Impact: NONE
  • Integrity Impact: PARTIAL
  • Availability Impact: NONE
Exploitability Score

8.6

Impact Score

2.9

Weaknesses
  • Type: Primary
    CWE-79

Affected Vendors & Products
Type Vendor Product Version/Range Vulnerable?
Application wso2 application_server 5.3.0 Yes
Application wso2 business_process_server 3.6.0 Yes
Application wso2 business_rules_server 2.2.0 Yes
Application wso2 complex_event_processor 4.2.0 Yes
Application wso2 dashboard_server 2.0.0 Yes
Application wso2 data_analytics_server 3.1.0 Yes
Application wso2 data_services_server 3.5.1 Yes
Application wso2 machine_learner 1.2.0 Yes

References