CVE-2017-14651

WSO2 Data Analytics Server 3.1.0 has XSS in carbon/resources/add_collection_ajaxprocessor.jsp via the collectionName or parentPath parameter.
References
Advertisement

NeevaHost hosting service

Configurations

Configuration 1 (hide)

OR cpe:2.3:a:wso2:enterprise_mobility_manager:2.2.0:*:*:*:*:*:*:*
cpe:2.3:a:wso2:data_services_server:3.5.1:*:*:*:*:*:*:*
cpe:2.3:a:wso2:api_manager:2.1.0:*:*:*:*:*:*:*
cpe:2.3:a:wso2:message_broker:3.2.0:*:*:*:*:*:*:*
cpe:2.3:a:wso2:machine_learner:1.2.0:*:*:*:*:*:*:*
cpe:2.3:a:wso2:iot_server:3.0.0:*:*:*:*:*:*:*
cpe:2.3:a:wso2:identity_server:5.3.0:*:*:*:*:*:*:*
cpe:2.3:a:wso2:complex_event_processor:4.2.0:*:*:*:*:*:*:*
cpe:2.3:a:wso2:business_rules_server:2.2.0:*:*:*:*:*:*:*
cpe:2.3:a:wso2:business_process_server:3.6.0:*:*:*:*:*:*:*
cpe:2.3:a:wso2:application_server:5.3.0:*:*:*:*:*:*:*
cpe:2.3:a:wso2:storage_server:1.5.0:*:*:*:*:*:*:*
cpe:2.3:a:wso2:governance_registry:5.4.0:*:*:*:*:*:*:*
cpe:2.3:a:wso2:enterprise_integrator:6.1.1:*:*:*:*:*:*:*
cpe:2.3:a:wso2:dashboard_server:2.0.0:*:*:*:*:*:*:*
cpe:2.3:a:wso2:app_manager:1.2.0:*:*:*:*:*:*:*
cpe:2.3:a:wso2:data_analytics_server:3.1.0:*:*:*:*:*:*:*

Information

Published : 2017-09-21 11:29

Updated : 2020-11-09 09:54


NVD link : CVE-2017-14651

Mitre link : CVE-2017-14651


JSON object : View

CWE
CWE-79

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')

Advertisement

dedicated server usa

Products Affected

wso2

  • enterprise_mobility_manager
  • business_rules_server
  • application_server
  • message_broker
  • api_manager
  • iot_server
  • app_manager
  • data_analytics_server
  • data_services_server
  • governance_registry
  • machine_learner
  • dashboard_server
  • business_process_server
  • identity_server
  • complex_event_processor
  • enterprise_integrator
  • storage_server