Vulnerability Description
WSO2 Data Analytics Server 3.1.0 has XSS in carbon/resources/add_collection_ajaxprocessor.jsp via the collectionName or parentPath parameter.
CVSS Score
MEDIUM
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Wso2 | Api Manager | 2.1.0 |
| Wso2 | App Manager | 1.2.0 |
| Wso2 | Application Server | 5.3.0 |
| Wso2 | Business Process Server | 3.6.0 |
| Wso2 | Business Rules Server | 2.2.0 |
| Wso2 | Complex Event Processor | 4.2.0 |
| Wso2 | Dashboard Server | 2.0.0 |
| Wso2 | Data Analytics Server | 3.1.0 |
| Wso2 | Data Services Server | 3.5.1 |
| Wso2 | Enterprise Integrator | 6.1.1 |
| Wso2 | Enterprise Mobility Manager | 2.2.0 |
| Wso2 | Governance Registry | 5.4.0 |
| Wso2 | Identity Server | 5.3.0 |
| Wso2 | Iot Server | 3.0.0 |
| Wso2 | Machine Learner | 1.2.0 |
| Wso2 | Message Broker | 3.2.0 |
| Wso2 | Storage Server | 1.5.0 |
Related Weaknesses (CWE)
References
- https://cybersecurityworks.com/zerodays/cve-2017-14651-wso2.htmlExploitThird Party Advisory
- https://docs.wso2.com/display/Security/Security+Advisory+WSO2-2017-0265PatchVendor Advisory
- https://github.com/cybersecurityworks/Disclosed/issues/15ExploitTechnical DescriptionThird Party Advisory
- https://cybersecurityworks.com/zerodays/cve-2017-14651-wso2.htmlExploitThird Party Advisory
- https://docs.wso2.com/display/Security/Security+Advisory+WSO2-2017-0265PatchVendor Advisory
- https://github.com/cybersecurityworks/Disclosed/issues/15ExploitTechnical DescriptionThird Party Advisory
FAQ
What is CVE-2017-14651?
CVE-2017-14651 is a vulnerability with a CVSS score of 4.8 (MEDIUM). WSO2 Data Analytics Server 3.1.0 has XSS in carbon/resources/add_collection_ajaxprocessor.jsp via the collectionName or parentPath parameter.
How severe is CVE-2017-14651?
CVE-2017-14651 has been rated MEDIUM with a CVSS base score of 4.8/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2017-14651?
Check the references section above for vendor advisories and patch information. Affected products include: Wso2 Api Manager, Wso2 App Manager, Wso2 Application Server, Wso2 Business Process Server, Wso2 Business Rules Server.