First published: Thu Jun 18 2020(Updated: )
An issue was discovered in WSO2 Identity Server through 5.9.0 and WSO2 IS as Key Manager through 5.9.0. A potential Reflected Cross-Site Scripting (XSS) vulnerability has been identified in the Management Console Policy Administration user interface.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
WSO2 Identity Server | <=5.9.0 | |
WSO2 Identity Server as Key Manager | <=5.9.0 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2020-14444 is a vulnerability discovered in WSO2 Identity Server through 5.9.0 and WSO2 IS as Key Manager through 5.9.0, which allows for potential Reflected Cross-Site Scripting (XSS) attacks in the Management Console Policy Administration user interface.
CVE-2020-14444 has a severity score of 5.4, which is considered medium.
CVE-2020-14444 affects WSO2 Identity Server versions up to and including 5.9.0 and WSO2 IS as Key Manager versions up to and including 5.9.0.
To fix CVE-2020-14444, it is recommended to upgrade WSO2 Identity Server and WSO2 IS as Key Manager to versions above 5.9.0, where the vulnerability has been patched.
For more information about CVE-2020-14444, you can refer to the following sources: - [Cybersecurity Works - Zero Days](https://cybersecurityworks.com/zerodays/cve-2020-14444-wso2.html) - [WSO2 Security Advisory WSO2-2020-0707](https://docs.wso2.com/display/Security/Security+Advisory+WSO2-2020-0707)