CVE-2020-24704: XSS
An issue was discovered in certain WSO2 products. The Try It tool allows Reflected XSS. This affects API Manager 2.2.0, API Manager Analytics 2.2.0, API Microgateway 2.2.0, Data Analytics Server 3.2.0, Enterprise Integrator through 6.6.0, IS as Key Manager 5.5.0, Identity Server 5.5.0 and 5.8.0, Identity Server Analytics 5.5.0, and IoT Server 3.3.0 and 3.3.1.
Affected Software
Event History
Frequently Asked Questions
What is CVE-2020-24704?
CVE-2020-24704 refers to an issue discovered in certain WSO2 products that allows Reflected XSS.
Which WSO2 products are affected by CVE-2020-24704?
CVE-2020-24704 affects the following WSO2 products: API Manager 2.2.0, API Manager Analytics 2.2.0, API Microgateway 2.2.0, Data Analytics Server 3.2.0, Enterprise Integrator through 6.6.0, IS as Key Manager 5.5.0, Identity Server 5.5.0 and 5.8.0, and IoT Server 3.3.0 and 3.3.1.
What is the severity of CVE-2020-24704?
CVE-2020-24704 has a severity level of 6.1 (medium).
How does CVE-2020-24704 affect WSO2 API Manager?
CVE-2020-24704 affects WSO2 API Manager version 2.2.0.
Is there a fix available for CVE-2020-24704?
Yes, a fix for CVE-2020-24704 is available. Please refer to the WSO2 Security Advisory WSO2-2020-0685 for more information.