CVE-2017-14995 Information

Description

The Management Console in WSO2 Application Server 5.3.0 WSO2 Business Process Server 3.6.0 WSO2 Business Rules Server 2.2.0 WSO2 Complex Event Processor 4.2.0 WSO2 Dashboard Server 2.0.0 WSO2 Data Analytics Server 3.1.0 WSO2 Data Services Server 3.5.1 and WSO2 Machine Learner 1.2.0 is affected by stored XSS.

CVSS Vector

CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N

Reference

https://docs.wso2.com/display/Security/Security+Advisory+WSO2-2017-0257

Attack Complexity

LOW

Privileges Required

NONE

User Interaction Required

NONE

Scope

REQUIRED

Confidentiality Impact

CHANGED

Integrity Impact

LOW

Availability Impact

LOW

Base Score

NONE

Base Severity

6.1

Share on: