First published: Wed Oct 04 2017(Updated: )
The Management Console in WSO2 Application Server 5.3.0, WSO2 Business Process Server 3.6.0, WSO2 Business Rules Server 2.2.0, WSO2 Complex Event Processor 4.2.0, WSO2 Dashboard Server 2.0.0, WSO2 Data Analytics Server 3.1.0, WSO2 Data Services Server 3.5.1, and WSO2 Machine Learner 1.2.0 is affected by stored XSS.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
WSO2 Application Server | =5.3.0 | |
WSO2 Business Process Server | =3.6.0 | |
WSO2 Business Rules Server | =2.2.0 | |
WSO2 Complex Event Processor | =4.2.0 | |
WSO2 Dashboard Server | =2.0.0 | |
WSO2 Data Analytics Server | =3.1.0 | |
WSO2 Data Services Server | =3.5.1 | |
WSO2 Machine Learner | =1.2.0 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2017-14995 is categorized as a moderate severity vulnerability.
To fix CVE-2017-14995, it is recommended to upgrade to the patched versions of affected WSO2 products.
CVE-2017-14995 affects WSO2 Application Server 5.3.0, Business Process Server 3.6.0, and several other WSO2 products.
CVE-2017-14995 is a security vulnerability in the Management Console of WSO2 products.
No specific workaround for CVE-2017-14995 is mentioned; upgrading is the recommended action.