CVE-2017-14651
21.09.2017, 18:29
WSO2 Data Analytics Server 3.1.0 has XSS in carbon/resources/add_collection_ajaxprocessor.jsp via the collectionName or parentPath parameter.
Vendor | Product | Version |
---|---|---|
wso2 | api_manager | 2.1.0 |
wso2 | app_manager | 1.2.0 |
wso2 | application_server | 5.3.0 |
wso2 | business_process_server | 3.6.0 |
wso2 | business_rules_server | 2.2.0 |
wso2 | complex_event_processor | 4.2.0 |
wso2 | dashboard_server | 2.0.0 |
wso2 | data_analytics_server | 3.1.0 |
wso2 | data_services_server | 3.5.1 |
wso2 | enterprise_integrator | 6.1.1 |
wso2 | enterprise_mobility_manager | 2.2.0 |
wso2 | governance_registry | 5.4.0 |
wso2 | identity_server | 5.3.0 |
wso2 | iot_server | 3.0.0 |
wso2 | machine_learner | 1.2.0 |
wso2 | message_broker | 3.2.0 |
wso2 | storage_server | 1.5.0 |
𝑥
= Vulnerable software versions
References