MEDIUM · 6.1

CVE-2017-14995

The Management Console in WSO2 Application Server 5.3.0, WSO2 Business Process Server 3.6.0, WSO2 Business Rules Server 2.2.0, WSO2 Complex Event Processor 4.2.0, WSO2 Dashboard Server 2.0.0, WSO2 Dat...

Vulnerability Description

The Management Console in WSO2 Application Server 5.3.0, WSO2 Business Process Server 3.6.0, WSO2 Business Rules Server 2.2.0, WSO2 Complex Event Processor 4.2.0, WSO2 Dashboard Server 2.0.0, WSO2 Data Analytics Server 3.1.0, WSO2 Data Services Server 3.5.1, and WSO2 Machine Learner 1.2.0 is affected by stored XSS.

CVSS Score

6.1

MEDIUM

CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
Attack Vector
NETWORK
Attack Complexity
LOW
Privileges Required
NONE
User Interaction
REQUIRED
Scope
CHANGED
Confidentiality
LOW
Integrity
LOW
Availability
NONE

Affected Products

VendorProductVersions
Wso2Application Server5.3.0
Wso2Business Process Server3.6.0
Wso2Business Rules Server2.2.0
Wso2Complex Event Processor4.2.0
Wso2Dashboard Server2.0.0
Wso2Data Analytics Server3.1.0
Wso2Data Services Server3.5.1
Wso2Machine Learner1.2.0

Related Weaknesses (CWE)

References

FAQ

What is CVE-2017-14995?

CVE-2017-14995 is a vulnerability with a CVSS score of 6.1 (MEDIUM). The Management Console in WSO2 Application Server 5.3.0, WSO2 Business Process Server 3.6.0, WSO2 Business Rules Server 2.2.0, WSO2 Complex Event Processor 4.2.0, WSO2 Dashboard Server 2.0.0, WSO2 Dat...

How severe is CVE-2017-14995?

CVE-2017-14995 has been rated MEDIUM with a CVSS base score of 6.1/10. Review the CVSS metrics above for detailed severity breakdown.

Is there a patch for CVE-2017-14995?

Check the references section above for vendor advisories and patch information. Affected products include: Wso2 Application Server, Wso2 Business Process Server, Wso2 Business Rules Server, Wso2 Complex Event Processor, Wso2 Dashboard Server.