CVE-2023-6835: Input Validation
Published Dec 15, 2023
·Updated
Multiple WSO2 products have been identified as vulnerable due to lack of server-side input validation in the Forum feature, API rating could be manipulated.
Affected Software
5 affected components
maven/org.wso2.carbon.apimgt:forum<=9.0.78
WSO2 API Manager=2.2.0
WSO2 API Manager=2.5.0
WSO2 API Manager=2.6.0
WSO2 IoT Server=3.3.1
Remediation
Information
For WSO2 Subscription holders, the recommended solution is to apply the provided patch/update to the affected versions of the products. If there are any instructions given with the patch/update, please make sure those are followed properly.
Community users may apply the relevant fixes to the product based on the public fix(s) advertised in https://security.docs.wso2.com/en/latest/security-announcements/security-advisories/2021/WSO2-2021-1... https://security.docs.wso2.com/en/latest/security-announcements/security-advisories/2021/WSO2-2021-1357/
Event History
Dec 15, 2023
CVE Published
09:16 AM
Data Sourced
09:16 AM
RemedyDescriptionSeverityWeakness
Advisory Published
12:30 PM
Frequently Asked Questions
1
What is the severity of CVE-2023-6835?
CVE-2023-6835 is classified as a critical vulnerability due to the potential for API rating manipulation.
2
How do I fix CVE-2023-6835?
To remediate CVE-2023-6835, update to the latest patched version of the affected WSO2 products.
3
Which products are affected by CVE-2023-6835?
CVE-2023-6835 affects multiple WSO2 products including API Manager versions 2.2.0, 2.5.0, and 2.6.0, as well as IoT Server version 3.3.1.
4
What types of vulnerabilities does CVE-2023-6835 involve?
CVE-2023-6835 involves a lack of server-side input validation in the Forum feature.
5
Can local users exploit CVE-2023-6835?
Yes, local users can exploit CVE-2023-6835 to manipulate API ratings due to insufficient input validation.