CVE-2016-4327: XSS
Cross-site scripting (XSS) vulnerability in WSO2 SOA Enablement Server for Java/6.6 build SSJ-6.6-20090827-1616 and earlier allows remote attackers to inject arbitrary web script or HTML via the PATHINFO.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2016-4327?
CVE-2016-4327 is classified as a medium severity cross-site scripting (XSS) vulnerability.
What systems are affected by CVE-2016-4327?
CVE-2016-4327 affects WSO2 SOA Enablement Server for Java versions up to and including 6.6 build SSJ-6.6-20090827-1616.
How do attackers exploit CVE-2016-4327?
Attackers exploit CVE-2016-4327 by injecting arbitrary web scripts or HTML into the application via the PATH_INFO variable.
How can I mitigate CVE-2016-4327?
Mitigation for CVE-2016-4327 involves upgrading to the latest version of WSO2 SOA Enablement Server that is not vulnerable to this XSS issue.
What are the potential impacts of CVE-2016-4327?
The potential impacts of CVE-2016-4327 include unauthorized data access and manipulation, which can lead to session hijacking and other malicious activities.