Vulmon
Recent Vulnerabilities
Research Posts
Trends
Blog
About
Contact
Vulmon Alerts
By Relevance
By Risk Score
By Publish Date
wso2 vulnerabilities and exploits
(subscribe to this query)
6.1
CVSSv3
CVE-2017-14995
The Management Console in WSO2 Application Server 5.3.0, WSO2 Business Process Server 3.6.0, WSO2 Business Rules Server 2.2.0, WSO2 Complex Event Processor 4.2.0, WSO2 Dashboard Server 2.0.0, WSO2 Data Analytics Server 3.1.0, WSO2 Data Services Server 3.5.1, and WSO2 Machine Lear...
Wso2 Data Analytics Server 3.1.0
Wso2 Dashboard Server 2.0.0
Wso2 Complex Event Processor 4.2.0
Wso2 Business Rules Server 2.2.0
Wso2 Data Services Server 3.5.1
Wso2 Business Process Server 3.6.0
Wso2 Machine Learner 1.2.0
Wso2 Application Server 5.3.0
4.8
CVSSv3
CVE-2017-14651
WSO2 Data Analytics Server 3.1.0 has XSS in carbon/resources/add_collection_ajaxprocessor.jsp via the collectionName or parentPath parameter.
Wso2 Enterprise Mobility Manager 2.2.0
Wso2 Data Services Server 3.5.1
Wso2 Api Manager 2.1.0
Wso2 Message Broker 3.2.0
Wso2 Machine Learner 1.2.0
Wso2 Iot Server 3.0.0
Wso2 Identity Server 5.3.0
Wso2 Complex Event Processor 4.2.0
Wso2 Business Rules Server 2.2.0
Wso2 Business Process Server 3.6.0
Wso2 Application Server 5.3.0
Wso2 Storage Server 1.5.0
Wso2 Governance Registry 5.4.0
Wso2 Enterprise Integrator 6.1.1
Wso2 Dashboard Server 2.0.0
Wso2 App Manager 1.2.0
Wso2 Data Analytics Server 3.1.0
7.5
CVSSv3
CVE-2016-4312
XML external entity (XXE) vulnerability in the XACML flow feature in WSO2 Identity Server 5.1.0 before WSO2-CARBON-PATCH-4.4.0-0231 allows remote authenticated users with access to XACML features to read arbitrary files, cause a denial of service, conduct server-side request forg...
Wso2 Identity Server 5.1.0
1 EDB exploit
8.8
CVSSv3
CVE-2016-4311
Cross-site request forgery (CSRF) vulnerability in the XACML flow feature in WSO2 Identity Server 5.1.0 allows remote malicious users to hijack the authentication of privileged users for requests that process XACML requests via an entitlement/eval-policy-submit.jsp request.
Wso2 Identity Server 5.1.0
1 EDB exploit
4.9
CVSSv3
CVE-2016-4314
Directory traversal vulnerability in the LogViewer Admin Service in WSO2 Carbon 4.4.5 allows remote authenticated administrators to read arbitrary files via a .. (dot dot) in the logFile parameter to downloadgz-ajaxprocessor.jsp.
Wso2 Carbon 4.4.5
1 EDB exploit
5.7
CVSSv3
CVE-2016-4315
Cross-site request forgery (CSRF) vulnerability in WSO2 Carbon 4.4.5 allows remote malicious users to hijack the authentication of privileged users for requests that shutdown a server via a shutdown action to server-admin/proxy_ajaxprocessor.jsp.
Wso2 Carbon 4.4.5
1 EDB exploit
6.1
CVSSv3
CVE-2016-4316
Multiple cross-site scripting (XSS) vulnerabilities in WSO2 Carbon 4.4.5 allow remote malicious users to inject arbitrary web script or HTML via the (1) setName parameter to identity-mgt/challenges-mgt.jsp; the (2) webappType or (3) httpPort parameter to webapp-list/webapp_info.j...
Wso2 Carbon 4.4.5
1 EDB exploit
6.1
CVSSv3
CVE-2016-4327
Cross-site scripting (XSS) vulnerability in WSO2 SOA Enablement Server for Java/6.6 build SSJ-6.6-20090827-1616 and previous versions allows remote malicious users to inject arbitrary web script or HTML via the PATH_INFO.
Wso2 Enablement Server For Java
CVSSv3
CVSSv2
CVSSv3
VMScore
Recommendations:
CVE-2023-52710
arbitrary
CVE-2024-5272
CVE-2024-2961
brute force
remote
CVE-2024-32944
CVE-2024-36241
CVE-2024-5274
Vulnerability Notification Service
You don’t have to wait for vulnerability scanning results
Get Started
« PREV
2
3
4
5
6
7