Show filters
64 Total Results
Displaying 51-60 of 64
Sort by:
Attacker Value
Unknown

CVE-2019-6516

Disclosure Date: May 14, 2019 (last updated November 27, 2024)
An issue was discovered in WSO2 Dashboard Server 2.0.0. It is possible to force the application to perform requests to the internal workstation (port-scanning) and to perform requests to adjacent workstations (network-scanning), aka SSRF.
0
Attacker Value
Unknown

CVE-2019-20443

Disclosure Date: May 08, 2019 (last updated February 21, 2025)
An issue was discovered in WSO2 API Manager 2.6.0, WSO2 Enterprise Integrator 6.5.0, WSO2 IS as Key Manager 5.7.0, and WSO2 Identity Server 5.8.0. A potential stored Cross-Site Scripting (XSS) vulnerability in mediaType has been identified in the registry UI.
Attacker Value
Unknown

CVE-2019-20439

Disclosure Date: May 08, 2019 (last updated February 21, 2025)
An issue was discovered in WSO2 API Manager 2.6.0. A potential Reflected Cross-Site Scripting (XSS) vulnerability has been identified in defining a scope in the "manage the API" page of the API Publisher.
Attacker Value
Unknown

CVE-2018-20737

Disclosure Date: March 21, 2019 (last updated November 27, 2024)
An issue was discovered in WSO2 API Manager 2.1.0 and 2.6.0. Reflected XSS exists in the carbon part of the product.
0
Attacker Value
Unknown

CVE-2018-20736

Disclosure Date: March 21, 2019 (last updated November 27, 2024)
An issue was discovered in WSO2 API Manager 2.1.0 and 2.6.0. A DOM-based XSS exists in the store part of the product.
0
Attacker Value
Unknown

CVE-2018-8716

Disclosure Date: April 25, 2018 (last updated November 26, 2024)
WSO2 Identity Server before 5.5.0 has XSS via the dashboard, allowing attacks by low-privileged attackers.
0
Attacker Value
Unknown

CVE-2017-14995

Disclosure Date: October 04, 2017 (last updated November 26, 2024)
The Management Console in WSO2 Application Server 5.3.0, WSO2 Business Process Server 3.6.0, WSO2 Business Rules Server 2.2.0, WSO2 Complex Event Processor 4.2.0, WSO2 Dashboard Server 2.0.0, WSO2 Data Analytics Server 3.1.0, WSO2 Data Services Server 3.5.1, and WSO2 Machine Learner 1.2.0 is affected by stored XSS.
0
Attacker Value
Unknown

CVE-2017-14651

Disclosure Date: September 21, 2017 (last updated November 26, 2024)
WSO2 Data Analytics Server 3.1.0 has XSS in carbon/resources/add_collection_ajaxprocessor.jsp via the collectionName or parentPath parameter.
Attacker Value
Unknown

CVE-2016-4314

Disclosure Date: February 17, 2017 (last updated November 26, 2024)
Directory traversal vulnerability in the LogViewer Admin Service in WSO2 Carbon 4.4.5 allows remote authenticated administrators to read arbitrary files via a .. (dot dot) in the logFile parameter to downloadgz-ajaxprocessor.jsp.
0
Attacker Value
Unknown

CVE-2016-4311

Disclosure Date: February 17, 2017 (last updated November 26, 2024)
Cross-site request forgery (CSRF) vulnerability in the XACML flow feature in WSO2 Identity Server 5.1.0 allows remote attackers to hijack the authentication of privileged users for requests that process XACML requests via an entitlement/eval-policy-submit.jsp request.
0