CVE-2017-14651

WSO2 Data Analytics Server 3.1.0 has XSS in carbon/resources/add_collection_ajaxprocessor.jsp via the collectionName or parentPath parameter.
Configurations

Configuration 1 (hide)

OR cpe:2.3:a:wso2:api_manager:2.1.0:*:*:*:*:*:*:*
cpe:2.3:a:wso2:app_manager:1.2.0:*:*:*:*:*:*:*
cpe:2.3:a:wso2:application_server:5.3.0:*:*:*:*:*:*:*
cpe:2.3:a:wso2:business_process_server:3.6.0:*:*:*:*:*:*:*
cpe:2.3:a:wso2:business_rules_server:2.2.0:*:*:*:*:*:*:*
cpe:2.3:a:wso2:complex_event_processor:4.2.0:*:*:*:*:*:*:*
cpe:2.3:a:wso2:dashboard_server:2.0.0:*:*:*:*:*:*:*
cpe:2.3:a:wso2:data_analytics_server:3.1.0:*:*:*:*:*:*:*
cpe:2.3:a:wso2:data_services_server:3.5.1:*:*:*:*:*:*:*
cpe:2.3:a:wso2:enterprise_integrator:6.1.1:*:*:*:*:*:*:*
cpe:2.3:a:wso2:enterprise_mobility_manager:2.2.0:*:*:*:*:*:*:*
cpe:2.3:a:wso2:governance_registry:5.4.0:*:*:*:*:*:*:*
cpe:2.3:a:wso2:identity_server:5.3.0:*:*:*:*:*:*:*
cpe:2.3:a:wso2:iot_server:3.0.0:*:*:*:*:*:*:*
cpe:2.3:a:wso2:machine_learner:1.2.0:*:*:*:*:*:*:*
cpe:2.3:a:wso2:message_broker:3.2.0:*:*:*:*:*:*:*
cpe:2.3:a:wso2:storage_server:1.5.0:*:*:*:*:*:*:*

History

21 Nov 2024, 03:13

Type Values Removed Values Added
References () https://cybersecurityworks.com/zerodays/cve-2017-14651-wso2.html - Exploit, Third Party Advisory () https://cybersecurityworks.com/zerodays/cve-2017-14651-wso2.html - Exploit, Third Party Advisory
References () https://docs.wso2.com/display/Security/Security+Advisory+WSO2-2017-0265 - Patch, Vendor Advisory () https://docs.wso2.com/display/Security/Security+Advisory+WSO2-2017-0265 - Patch, Vendor Advisory
References () https://github.com/cybersecurityworks/Disclosed/issues/15 - Exploit, Technical Description, Third Party Advisory () https://github.com/cybersecurityworks/Disclosed/issues/15 - Exploit, Technical Description, Third Party Advisory

Information

Published : 2017-09-21 18:29

Updated : 2024-11-21 03:13


NVD link : CVE-2017-14651

Mitre link : CVE-2017-14651

CVE.ORG link : CVE-2017-14651


JSON object : View

Products Affected

wso2

  • iot_server
  • api_manager
  • application_server
  • data_analytics_server
  • complex_event_processor
  • business_rules_server
  • enterprise_integrator
  • governance_registry
  • data_services_server
  • machine_learner
  • app_manager
  • business_process_server
  • dashboard_server
  • message_broker
  • identity_server
  • storage_server
  • enterprise_mobility_manager
CWE
CWE-79

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')