Vulmon
Recent Vulnerabilities
Research Posts
Trends
Blog
About
Contact
Vulmon Alerts
By Relevance
By Risk Score
By Publish Date
wso2 identity server 5.7.0 vulnerabilities and exploits
(subscribe to this query)
312
VMScore
CVE-2018-20737
An issue exists in WSO2 API Manager 2.1.0 and 2.6.0. Reflected XSS exists in the carbon part of the product.
Wso2 Identity Server 5.7.0
Wso2 Api Manager 2.6.0
Wso2 Identity Server As Key Manager 5.7.0
383
VMScore
CVE-2019-20436
An issue exists in WSO2 API Manager 2.6.0, WSO2 IS as Key Manager 5.7.0, and WSO2 Identity Server 5.8.0. If there is a claim dialect configured with an XSS payload in the dialect URI, and a user picks up this dialect's URI and adds it as the service provider claim dialect wh...
Wso2 Api Manager 2.6.0
Wso2 Identity Server 5.7.0
Wso2 Identity Server 5.8.0
383
VMScore
CVE-2019-20437
An issue exists in WSO2 API Manager 2.6.0, WSO2 IS as Key Manager 5.7.0, and WSO2 Identity Server 5.8.0. When a custom claim dialect with an XSS payload is configured in the identity provider basic claim configuration, that payload gets executed, if a user picks up that dialect...
Wso2 Api Manager 2.6.0
Wso2 Identity Server 5.7.0
Wso2 Identity Server 5.8.0
570
VMScore
CVE-2021-42646
XML External Entity (XXE) vulnerability in the file based service provider creation feature of the Management Console in WSO2 API Manager 2.6.0, 3.0.0, 3.1.0, 3.2.0, and 4.0.0; and WSO2 IS as Key Manager 5.7.0, 5.9.0, and 5.10.0; and WSO2 Identity Server 5.7.0, 5.8.0, 5.9.0, 5.10...
Wso2 Api Manager 2.6.0
Wso2 Identity Server 5.7.0
Wso2 Identity Server As Key Manager 5.7.0
Wso2 Identity Server 5.8.0
Wso2 Api Manager 3.0.0
Wso2 Api Manager 3.1.0
Wso2 Identity Server As Key Manager 5.9.0
Wso2 Identity Server As Key Manager 5.10.0
Wso2 Identity Server 5.11.0
Wso2 Api Manager 4.0.0
Wso2 Api Manager 3.2.0
Wso2 Identity Server 5.9.0
Wso2 Identity Server 5.10.0
312
VMScore
CVE-2019-20442
An issue exists in WSO2 API Manager 2.6.0, WSO2 Enterprise Integrator 6.5.0, WSO2 IS as Key Manager 5.7.0, and WSO2 Identity Server 5.8.0. A potential stored Cross-Site Scripting (XSS) vulnerability in roleToAuthorize has been identified in the registry UI.
Wso2 Api Manager 2.6.0
Wso2 Enterprise Integrator 6.5.0
Wso2 Identity Server 5.7.0
Wso2 Identity Server 5.8.0
312
VMScore
CVE-2019-20443
An issue exists in WSO2 API Manager 2.6.0, WSO2 Enterprise Integrator 6.5.0, WSO2 IS as Key Manager 5.7.0, and WSO2 Identity Server 5.8.0. A potential stored Cross-Site Scripting (XSS) vulnerability in mediaType has been identified in the registry UI.
Wso2 Api Manager 2.6.0
Wso2 Enterprise Integrator 6.5.0
Wso2 Identity Server 5.7.0
Wso2 Identity Server 5.8.0
1 Github repository
383
VMScore
CVE-2019-18882
WSO2 IS as Key Manager 5.7.0 allows stored XSS in download-userinfo.jag because Content-Type is mishandled.
Wso2 Identity Server 5.7.0
383
VMScore
CVE-2019-18881
WSO2 IS as Key Manager 5.7.0 allows unauthenticated reflected XSS in the dashboard user profile.
Wso2 Identity Server 5.7.0
NA
CVE-2023-6837
Multiple WSO2 products have been identified as vulnerable to perform user impersonatoin using JIT provisioning. In order for this vulnerability to have any impact on your deployment, following conditions must be met: * An IDP configured for federated authentication and JIT provis...
Wso2 Api Manager 2.6.0
Wso2 Api Manager 3.0.0
Wso2 Api Manager 3.1.0
Wso2 Api Manager 4.0.0
Wso2 Api Manager 3.2.0
Wso2 Api Manager 2.5.0
Wso2 Identity Server 5.7.0
Wso2 Identity Server 5.8.0
Wso2 Identity Server 5.11.0
Wso2 Identity Server 5.9.0
Wso2 Identity Server 5.10.0
Wso2 Identity Server 5.6.0
Wso2 Identity Server As Key Manager 5.7.0
Wso2 Identity Server As Key Manager 5.6.0
Wso2 Identity Server As Key Manager 5.9.0
Wso2 Identity Server As Key Manager 5.10.0
383
VMScore
CVE-2021-36760
In accountrecoveryendpoint/recoverpassword.do in WSO2 Identity Server 5.7.0, it is possible to perform a DOM-Based XSS attack affecting the callback parameter modifying the URL that precedes the callback parameter. Once the username or password reset procedure is completed, the J...
Wso2 Api Manager 3.0.0
Wso2 Api Manager 3.1.0
Wso2 Api Manager 3.2.0
Wso2 Api Manager 4.0.0
Wso2 Identity Server 5.7.0
Wso2 Identity Server 5.8.0
Wso2 Identity Server 5.9.0
Wso2 Identity Server 5.10.0
Wso2 Identity Server 5.11.0
Wso2 Identity Server As Key Manager 5.3.0
Wso2 Identity Server As Key Manager 5.5.0
Wso2 Identity Server As Key Manager 5.6.0
Wso2 Identity Server As Key Manager 5.7.0
Wso2 Identity Server As Key Manager 5.9.0
Wso2 Identity Server As Key Manager 5.10.0
Wso2 Iot Server 3.3.1
VMScore
CVSSv2
CVSSv3
VMScore
Recommendations:
CVE-2024-4761
command injection
CVE-2024-3676
IDOR
CVE-2024-30039
CVE-2024-32113
CVE-2024-30049
CVE-2024-4776
SQL injection
Vulnerability Notification Service
You don’t have to wait for vulnerability scanning results
Get Started
1
2
NEXT »