- Description
- An issue was discovered in certain WSO2 products. The Try It tool allows Reflected XSS. This affects API Manager through 3.1.0, API Manager Analytics 2.5.0, IS as Key Manager through 5.10.0, Identity Server through 5.10.0, Identity Server Analytics through 5.6.0, and IoT Server 3.1.0.
- Source
- cve@mitre.org
- NVD status
- Modified
CVSS 3.1
- Type
- Primary
- Base score
- 6.1
- Impact score
- 2.7
- Exploitability score
- 2.8
- Vector string
- CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
- Severity
- MEDIUM
CVSS 2.0
- Type
- Primary
- Base score
- 4.3
- Impact score
- 2.9
- Exploitability score
- 8.6
- Vector string
- AV:N/AC:M/Au:N/C:N/I:P/A:N
- nvd@nist.gov
- CWE-79
- Hype score
- Not currently trending
[
{
"nodes": [
{
"negate": false,
"cpeMatch": [
{
"criteria": "cpe:2.3:a:wso2:api_manager:*:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "E2E71049-86F8-479F-8D9D-2D67B2CC6EB4",
"versionEndIncluding": "3.1.0"
},
{
"criteria": "cpe:2.3:a:wso2:api_manager_analytics:2.5.0:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "04A2A50A-872E-4CC7-BBB7-3E0956176AAC"
},
{
"criteria": "cpe:2.3:a:wso2:identity_server:*:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "5601E5C8-011F-4FF3-A327-3B2D637EAC79",
"versionEndIncluding": "5.10.0"
},
{
"criteria": "cpe:2.3:a:wso2:identity_server_analytics:*:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "05810F17-3BC8-400A-92BF-0D51E3580409",
"versionEndIncluding": "5.6.0"
},
{
"criteria": "cpe:2.3:a:wso2:identity_server_as_key_manager:*:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "78933A5F-C186-47B9-8EC3-161C4451B719",
"versionEndIncluding": "5.10.0"
},
{
"criteria": "cpe:2.3:a:wso2:iot_server:3.1.0:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "663657FF-9D02-49A2-B988-315D52D7E220"
}
],
"operator": "OR"
}
]
}
]