Vulnerabilities > Wso2 > API Manager

DATE CVE VULNERABILITY TITLE RISK
2023-12-18 CVE-2023-6911 Cross-site Scripting vulnerability in Wso2 products
Multiple WSO2 products have been identified as vulnerable due to improper output encoding, a Stored Cross Site Scripting (XSS) attack can be carried out by an attacker injecting a malicious payload into the Registry feature of the Management Console.
network
low complexity
wso2 CWE-79
4.8
2023-12-15 CVE-2023-6839 Information Exposure Through an Error Message vulnerability in Wso2 API Manager
Due to improper error handling, a REST API resource could expose a server side error containing an internal WSO2 specific package name in the HTTP response.
network
low complexity
wso2 CWE-209
5.3
2023-12-15 CVE-2023-6835 Improper Input Validation vulnerability in Wso2 API Manager and IOT Server
Multiple WSO2 products have been identified as vulnerable due to lack of server-side input validation in the Forum feature, API rating could be manipulated.
network
low complexity
wso2 CWE-20
5.3
2023-12-15 CVE-2023-6836 XXE vulnerability in Wso2 products
Multiple WSO2 products have been identified as vulnerable due to an XML External Entity (XXE) attack abuses a widely available but rarely used feature of XML parsers to access sensitive information.
network
low complexity
wso2 CWE-611
7.5
2023-12-15 CVE-2023-6837 Unspecified vulnerability in Wso2 products
Multiple WSO2 products have been identified as vulnerable to perform user impersonatoin using JIT provisioning. In order for this vulnerability to have any impact on your deployment, following conditions must be met: * An IDP configured for federated authentication and JIT provisioning enabled with the "Prompt for username, password and consent" option. * A service provider that uses the above IDP for federated authentication and has the "Assert identity using mapped local subject identifier" flag enabled. Attacker should have: * A fresh valid user account in the federated IDP that has not been used earlier. * Knowledge of the username of a valid user in the local IDP. When all preconditions are met, a malicious actor could use JIT provisioning flow to perform user impersonation.
network
high complexity
wso2
8.2
2023-12-15 CVE-2023-6838 Cross-site Scripting vulnerability in Wso2 products
Reflected XSS vulnerability can be exploited by tampering a request parameter in Authentication Endpoint.
network
low complexity
wso2 CWE-79
6.1
2023-05-23 CVE-2023-31664 Cross-site Scripting vulnerability in Wso2 API Manager
A reflected cross-site scripting (XSS) vulnerability in /authenticationendpoint/login.do of WSO2 API Manager before 4.2.0 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the tenantDomain parameter.
network
low complexity
wso2 CWE-79
6.1
2022-05-11 CVE-2021-42646 XXE vulnerability in Wso2 products
XML External Entity (XXE) vulnerability in the file based service provider creation feature of the Management Console in WSO2 API Manager 2.6.0, 3.0.0, 3.1.0, 3.2.0, and 4.0.0; and WSO2 IS as Key Manager 5.7.0, 5.9.0, and 5.10.0; and WSO2 Identity Server 5.7.0, 5.8.0, 5.9.0, 5.10.0, and 5.11.0.
network
low complexity
wso2 CWE-611
critical
9.1
2022-04-21 CVE-2022-29548 Cross-site Scripting vulnerability in Wso2 products
A reflected XSS issue exists in the Management Console of several WSO2 products.
network
low complexity
wso2 CWE-79
6.1
2022-04-18 CVE-2022-29464 Path Traversal vulnerability in Wso2 products
Certain WSO2 products allow unrestricted file upload with resultant remote code execution.
network
low complexity
wso2 CWE-22
critical
9.8