CVE-2020-14445: XSS
An issue was discovered in WSO2 Identity Server through 5.9.0 and WSO2 IS as Key Manager through 5.9.0. A potential Reflected Cross-Site Scripting (XSS) vulnerability has been identified in the Management Console Basic Policy Editor user Interface.
Affected Software
Event History
Frequently Asked Questions
What is CVE-2020-14445?
CVE-2020-14445 is a potential Reflected Cross-Site Scripting (XSS) vulnerability in the Management Console Basic Policy Editor user interface of WSO2 Identity Server and WSO2 IS as Key Manager.
What is the severity of CVE-2020-14445?
The severity of CVE-2020-14445 is medium, with a CVSS score of 5.4.
Which versions of WSO2 Identity Server are affected by CVE-2020-14445?
WSO2 Identity Server versions up to and including 5.9.0 are affected by CVE-2020-14445.
Which versions of WSO2 Identity Server as Key Manager are affected by CVE-2020-14445?
WSO2 Identity Server as Key Manager versions up to and including 5.9.0 are affected by CVE-2020-14445.
How can I fix CVE-2020-14445?
To fix CVE-2020-14445, it is recommended to upgrade WSO2 Identity Server and WSO2 IS as Key Manager to a version higher than 5.9.0.