CVE-2017-14995
Summary
| CVE | CVE-2017-14995 |
|---|---|
| State | PUBLIC |
| Assigner | [email protected] |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2017-10-04 01:29:00 UTC |
| Updated | 2017-10-23 11:47:00 UTC |
| Description | The Management Console in WSO2 Application Server 5.3.0, WSO2 Business Process Server 3.6.0, WSO2 Business Rules Server 2.2.0, WSO2 Complex Event Processor 4.2.0, WSO2 Dashboard Server 2.0.0, WSO2 Data Analytics Server 3.1.0, WSO2 Data Services Server 3.5.1, and WSO2 Machine Learner 1.2.0 is affected by stored XSS. |
Risk And Classification
Problem Types: CWE-79
NVD Known Affected Configurations (CPE 2.3)
| Type | Vendor | Product | Version | Update | Edition | Language |
|---|---|---|---|---|---|---|
| Application | Wso2 | Application Server | 5.3.0 | All | All | All |
| Application | Wso2 | Application Server | 5.3.0 | All | All | All |
| Application | Wso2 | Business Process Server | 3.6.0 | All | All | All |
| Application | Wso2 | Business Process Server | 3.6.0 | All | All | All |
| Application | Wso2 | Business Rules Server | 2.2.0 | All | All | All |
| Application | Wso2 | Business Rules Server | 2.2.0 | All | All | All |
| Application | Wso2 | Complex Event Processor | 4.2.0 | All | All | All |
| Application | Wso2 | Complex Event Processor | 4.2.0 | All | All | All |
| Application | Wso2 | Dashboard Server | 2.0.0 | All | All | All |
| Application | Wso2 | Dashboard Server | 2.0.0 | All | All | All |
| Application | Wso2 | Data Analytics Server | 3.1.0 | All | All | All |
| Application | Wso2 | Data Analytics Server | 3.1.0 | All | All | All |
| Application | Wso2 | Data Services Server | 3.5.1 | All | All | All |
| Application | Wso2 | Data Services Server | 3.5.1 | All | All | All |
| Application | Wso2 | Machine Learner | 1.2.0 | All | All | All |
| Application | Wso2 | Machine Learner | 1.2.0 | All | All | All |
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| Security Advisory WSO2-2017-0257 - WSO2 Platform Security - WSO2 Documentation | CONFIRM | docs.wso2.com | Patch, Vendor Advisory |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
No vendor comments have been submitted for this CVE.
There are currently no legacy QID mappings associated with this CVE.