CVE-2020-14444: XSS
An issue was discovered in WSO2 Identity Server through 5.9.0 and WSO2 IS as Key Manager through 5.9.0. A potential Reflected Cross-Site Scripting (XSS) vulnerability has been identified in the Management Console Policy Administration user interface.
Affected Software
Event History
Frequently Asked Questions
What is CVE-2020-14444?
CVE-2020-14444 is a vulnerability discovered in WSO2 Identity Server through 5.9.0 and WSO2 IS as Key Manager through 5.9.0, which allows for potential Reflected Cross-Site Scripting (XSS) attacks in the Management Console Policy Administration user interface.
How severe is CVE-2020-14444?
CVE-2020-14444 has a severity score of 5.4, which is considered medium.
Which software versions are affected by CVE-2020-14444?
CVE-2020-14444 affects WSO2 Identity Server versions up to and including 5.9.0 and WSO2 IS as Key Manager versions up to and including 5.9.0.
How can I fix CVE-2020-14444?
To fix CVE-2020-14444, it is recommended to upgrade WSO2 Identity Server and WSO2 IS as Key Manager to versions above 5.9.0, where the vulnerability has been patched.
Is there any additional information about CVE-2020-14444?
For more information about CVE-2020-14444, you can refer to the following sources: - [Cybersecurity Works - Zero Days](https://cybersecurityworks.com/zerodays/cve-2020-14444-wso2.html) - [WSO2 Security Advisory WSO2-2020-0707](https://docs.wso2.com/display/Security/Security+Advisory+WSO2-2020-0707)