First published: Thu Jun 18 2020(Updated: )
An issue was discovered in WSO2 Identity Server through 5.9.0 and WSO2 IS as Key Manager through 5.9.0. A potential Reflected Cross-Site Scripting (XSS) vulnerability has been identified in the Management Console Basic Policy Editor user Interface.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
WSO2 Identity Server | <=5.9.0 | |
WSO2 Identity Server as Key Manager | <=5.9.0 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2020-14445 is a potential Reflected Cross-Site Scripting (XSS) vulnerability in the Management Console Basic Policy Editor user interface of WSO2 Identity Server and WSO2 IS as Key Manager.
The severity of CVE-2020-14445 is medium, with a CVSS score of 5.4.
WSO2 Identity Server versions up to and including 5.9.0 are affected by CVE-2020-14445.
WSO2 Identity Server as Key Manager versions up to and including 5.9.0 are affected by CVE-2020-14445.
To fix CVE-2020-14445, it is recommended to upgrade WSO2 Identity Server and WSO2 IS as Key Manager to a version higher than 5.9.0.