Vulnerability index

Browse CVEs

108 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Api Manager HIGH 8.2
CVE-2023-6837

Multiple WSO2 products have been identified as vulnerable to perform user impersonatoin using JIT provisioning. In order for this vulnerability to ha…

Fix: 2.5.0.32 / 2.6.0.52+
Fix from $1,950 2023-12-15
Api Manager HIGH 7.5
CVE-2023-6836

Multiple WSO2 products have been identified as vulnerable due to an XML External Entity (XXE) attack abuses a widely available but rarely used featur…

Fix: after 6.6.0
Fix from $1,950 2023-12-15
Api Manager MEDIUM 5.3
CVE-2023-6835

Multiple WSO2 products have been identified as vulnerable due to lack of server-side input validation in the Forum feature, API rating could be manip…

Mitigation only
Fix from $1,600 2023-12-15
Api Manager MEDIUM 6.1
CVE-2023-31664

A reflected cross-site scripting (XSS) vulnerability in /authenticationendpoint/login.do of WSO2 API Manager before 4.2.0 allows attackers to execute…

Fix: 4.2.0+
Fix from $1,600 2023-05-23
Carbon Registry MEDIUM 6.1
CVE-2022-4520

A vulnerability was found in WSO2 carbon-registry up to 4.8.11. It has been rated as problematic. Affected by this issue is some unknown functionalit…

Fix: 4.8.12+
Fix from $1,600 2022-12-15
Carbon Registry MEDIUM 6.1
CVE-2022-4521

A vulnerability classified as problematic has been found in WSO2 carbon-registry up to 4.8.6. This affects an unknown part of the component Request P…

Fix: 4.8.7+
Fix from $1,600 2022-12-15
Enterprise Integrator MEDIUM 6.1
CVE-2022-39809

An issue was discovered in WSO2 Enterprise Integrator 6.4.0. A Reflected Cross-Site Scripting (XSS) vulnerability has been identified in the Manageme…

Mitigation only
Fix from $1,600 2022-09-09
Enterprise Integrator MEDIUM 6.1
CVE-2022-39810EPSS 57%

An issue was discovered in WSO2 Enterprise Integrator 6.4.0. A Reflected Cross-Site Scripting (XSS) vulnerability has been identified in the Manageme…

Mitigation only
Fix from $1,600 2022-09-09
Api Manager CRITICAL 9.1
CVE-2021-42646

XML External Entity (XXE) vulnerability in the file based service provider creation feature of the Management Console in WSO2 API Manager 2.6.0, 3.0.…

Patch available
Fix from $2,300 2022-05-11
Api Manager MEDIUM 6.1
CVE-2022-29548EPSS 41%

A reflected XSS issue exists in the Management Console of several WSO2 products. This affects API Manager 2.2.0, 2.5.0, 2.6.0, 3.0.0, 3.1.0, 3.2.0, a…

No fix yet
Fix from $1,600 2022-04-21
Api Manager CRITICAL 9.8
CVE-2022-29464 KEVEPSS 100%

Certain WSO2 products allow unrestricted file upload with resultant remote code execution. The attacker must use a /fileupload endpoint with a Conten…

Fix: after 6.6.0
Fix from $2,300 2022-04-18
Api Manager MEDIUM 6.1
CVE-2021-36760

In accountrecoveryendpoint/recoverpassword.do in WSO2 Identity Server 5.7.0, it is possible to perform a DOM-Based XSS attack affecting the callback …

Mitigation only
Fix from $1,600 2021-12-07
Api Manager MEDIUM 6.1
CVE-2020-17453EPSS 26%

WSO2 Management Console through 5.10 allows XSS via the carbon/admin/login.jsp msgId parameter.

Fix: after 6.6.0
Fix from $1,600 2021-04-05
Api Manager MEDIUM 6.1
CVE-2020-27885

Cross-Site Scripting (XSS) vulnerability on WSO2 API Manager 3.1.0. By exploiting a Cross-site scripting vulnerability the attacker can hijack a logg…

No fix yet
Fix from $1,600 2020-10-29
Enterprise Integrator MEDIUM 5.4
CVE-2020-25516

WSO2 Enterprise Integrator 6.6.0 or earlier contains a stored cross-site scripting (XSS) vulnerability in BPMN explorer tasks.

Fix: after 6.6.0
Fix from $1,600 2020-10-29
Api Manager MEDIUM 6.1
CVE-2020-17454

WSO2 API Manager 3.1.0 and earlier has reflected XSS on the "publisher" component's admin interface. More precisely, it is possible to inject an XSS …

Fix: after 3.1.0
Fix from $1,600 2020-10-21
Api Manager HIGH 8.8
CVE-2020-24703

An issue was discovered in certain WSO2 products. A valid Carbon Management Console session cookie may be sent to an attacker-controlled server if th…

Fix: after 6.6.0
Fix from $1,950 2020-08-27
Api Manager HIGH 8.8
CVE-2020-24705

An issue was discovered in certain WSO2 products. A valid Carbon Management Console session cookie may be sent to an attacker-controlled server if th…

Fix: after 5.10.0
Fix from $1,950 2020-08-27
Api Manager MEDIUM 6.1
CVE-2020-24704

An issue was discovered in certain WSO2 products. The Try It tool allows Reflected XSS. This affects API Manager 2.2.0, API Manager Analytics 2.2.0, …

Fix: after 6.6.0
Fix from $1,600 2020-08-27
Api Manager MEDIUM 6.1
CVE-2020-24706

An issue was discovered in certain WSO2 products. The Try It tool allows Reflected XSS. This affects API Manager through 3.1.0, API Manager Analytics…

Fix: after 5.10.0
Fix from $1,600 2020-08-27
Api Manager CRITICAL 9.1
CVE-2020-24590

The Management Console in WSO2 API Manager through 3.1.0 and API Microgateway 2.2.0 allows XML Entity Expansion attacks.

Fix: after 3.1.0
Fix from $2,300 2020-08-21
Api Manager MEDIUM 6.5
CVE-2020-24591

The Management Console in certain WSO2 products allows XXE attacks during EventReceiver updates. This affects API Manager through 3.0.0, API Manager …

Fix: after 5.6.0
Fix from $1,600 2020-08-21
Api Manager CRITICAL 9.1
CVE-2020-24589EPSS 26%

The Management Console in WSO2 API Manager through 3.1.0 and API Microgateway 2.2.0 allows XML External Entity injection (XXE) attacks.

Fix: after 3.1.0
Fix from $2,300 2020-08-21
Identity Server MEDIUM 6.1
CVE-2020-14446

An issue was discovered in WSO2 Identity Server through 5.10.0 and WSO2 IS as Key Manager through 5.10.0. An open redirect exists.

Fix: after 5.10.0
Fix from $1,600 2020-06-18
Identity Server MEDIUM 5.4
CVE-2020-14444

An issue was discovered in WSO2 Identity Server through 5.9.0 and WSO2 IS as Key Manager through 5.9.0. A potential Reflected Cross-Site Scripting (X…

Fix: after 5.9.0
Fix from $1,600 2020-06-18
Identity Server MEDIUM 5.4
CVE-2020-14445

An issue was discovered in WSO2 Identity Server through 5.9.0 and WSO2 IS as Key Manager through 5.9.0. A potential Reflected Cross-Site Scripting (X…

Fix: after 5.9.0
Fix from $1,600 2020-06-18
Api Manager MEDIUM 6.7
CVE-2020-13883

In WSO2 API Manager 3.0.0 and earlier, WSO2 API Microgateway 2.2.0, and WSO2 IS as Key Manager 5.9.0 and earlier, Management Console allows XXE durin…

Fix: after 5.9.0
Fix from $1,600 2020-06-06
Api Manager CRITICAL 9.8
CVE-2020-13226

WSO2 API Manager 3.0.0 does not properly restrict outbound network access from a Publisher node, opening up the possibility of SSRF to this node's en…

Mitigation only
Fix from $2,300 2020-05-20
Api Manager HIGH 7.2
CVE-2020-12719

XXE during an EventPublisher update can occur in Management Console in WSO2 API Manager 3.0.0 and earlier, API Manager Analytics 2.5.0 and earlier, A…

Fix: after 6.4.0
Fix from $1,950 2020-05-08
Enterprise Integrator HIGH 7.2
CVE-2020-11885

WSO2 Enterprise Integrator through 6.6.0 has an XXE vulnerability where a user (with admin console access) can use the XML validator to make unintend…

Fix: after 6.6.0
Fix from $1,950 2020-04-17