CVE-2017-14651: XSS
Published Sep 21, 2017
·Updated
WSO2 Data Analytics Server 3.1.0 has XSS in carbon/resources/addcollectionajaxprocessor.jsp via the collectionName or parentPath parameter.
Affected Software
17 affected components
WSO2 API Manager=2.1.0
WSO2 App Manager=1.2.0
WSO2 Application Server=5.3.0
WSO2 Business Process Server=3.6.0
WSO2 Business Rules Server=2.2.0
WSO2 Complex Event Processor=4.2.0
WSO2 Dashboard Server=2.0.0
WSO2 Data Analytics Server=3.1.0
WSO2 Data Services Server=3.5.1
WSO2 Enterprise Integrator=6.1.1
WSO2 Enterprise Mobility Manager=2.2.0
WSO2 Governance Registry=5.4.0
WSO2 Identity Server=5.3.0
WSO2 IoT Server=3.0.0
WSO2 Machine Learner=1.2.0
WSO2 Message Broker=3.2.0
WSO2 Storage Server=1.5.0
Remediation
Event History
Sep 21, 2017
CVE Published
via MITRE·06:00 PM
Data Sourced
via MITRE·06:00 PM
Description
Frequently Asked Questions
1
What is the severity of CVE-2017-14651?
CVE-2017-14651 has a medium severity rating due to its potential for XSS attacks.
2
What systems are affected by CVE-2017-14651?
CVE-2017-14651 affects WSO2 Data Analytics Server version 3.1.0 and various other WSO2 software applications.
3
How do I fix CVE-2017-14651?
To fix CVE-2017-14651, you should upgrade to the latest version of the affected WSO2 products that includes the relevant security patches.
4
What type of vulnerability is CVE-2017-14651?
CVE-2017-14651 is a Cross-Site Scripting (XSS) vulnerability.
5
What are the consequences of exploiting CVE-2017-14651?
Exploiting CVE-2017-14651 could allow an attacker to execute arbitrary scripts in the context of the user's session, potentially compromising user accounts.