Vulnerability Description
The Management Console in WSO2 Application Server 5.3.0, WSO2 Business Process Server 3.6.0, WSO2 Business Rules Server 2.2.0, WSO2 Complex Event Processor 4.2.0, WSO2 Dashboard Server 2.0.0, WSO2 Data Analytics Server 3.1.0, WSO2 Data Services Server 3.5.1, and WSO2 Machine Learner 1.2.0 is affected by stored XSS.
CVSS Score
MEDIUM
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Wso2 | Application Server | 5.3.0 |
| Wso2 | Business Process Server | 3.6.0 |
| Wso2 | Business Rules Server | 2.2.0 |
| Wso2 | Complex Event Processor | 4.2.0 |
| Wso2 | Dashboard Server | 2.0.0 |
| Wso2 | Data Analytics Server | 3.1.0 |
| Wso2 | Data Services Server | 3.5.1 |
| Wso2 | Machine Learner | 1.2.0 |
Related Weaknesses (CWE)
References
- https://docs.wso2.com/display/Security/Security+Advisory+WSO2-2017-0257PatchVendor Advisory
- https://docs.wso2.com/display/Security/Security+Advisory+WSO2-2017-0257PatchVendor Advisory
FAQ
What is CVE-2017-14995?
CVE-2017-14995 is a vulnerability with a CVSS score of 6.1 (MEDIUM). The Management Console in WSO2 Application Server 5.3.0, WSO2 Business Process Server 3.6.0, WSO2 Business Rules Server 2.2.0, WSO2 Complex Event Processor 4.2.0, WSO2 Dashboard Server 2.0.0, WSO2 Dat...
How severe is CVE-2017-14995?
CVE-2017-14995 has been rated MEDIUM with a CVSS base score of 6.1/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2017-14995?
Check the references section above for vendor advisories and patch information. Affected products include: Wso2 Application Server, Wso2 Business Process Server, Wso2 Business Rules Server, Wso2 Complex Event Processor, Wso2 Dashboard Server.