First published: Thu Sep 21 2017(Updated: )
WSO2 Data Analytics Server 3.1.0 has XSS in carbon/resources/add_collection_ajaxprocessor.jsp via the collectionName or parentPath parameter.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
WSO2 API Manager | =2.1.0 | |
Wso2 App Manager | =1.2.0 | |
WSO2 Application Server | =5.3.0 | |
WSO2 Business Process Server | =3.6.0 | |
WSO2 Business Rules Server | =2.2.0 | |
WSO2 Complex Event Processor | =4.2.0 | |
WSO2 Dashboard Server | =2.0.0 | |
WSO2 Data Analytics Server | =3.1.0 | |
WSO2 Data Services Server | =3.5.1 | |
WSO2 Enterprise Integrator | =6.1.1 | |
Wso2 Enterprise Mobility Manager | =2.2.0 | |
Wso2 Governance Registry | =5.4.0 | |
WSO2 Identity Server | =5.3.0 | |
Wso2 Iot Server | =3.0.0 | |
WSO2 Machine Learner | =1.2.0 | |
Wso2 Message Broker | =3.2.0 | |
Wso2 Storage Server | =1.5.0 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2017-14651 has a medium severity rating due to its potential for XSS attacks.
CVE-2017-14651 affects WSO2 Data Analytics Server version 3.1.0 and various other WSO2 software applications.
To fix CVE-2017-14651, you should upgrade to the latest version of the affected WSO2 products that includes the relevant security patches.
CVE-2017-14651 is a Cross-Site Scripting (XSS) vulnerability.
Exploiting CVE-2017-14651 could allow an attacker to execute arbitrary scripts in the context of the user's session, potentially compromising user accounts.