Vulnerabilities > Wso2 > Business Process Server

DATE CVE VULNERABILITY TITLE RISK
2017-10-04 CVE-2017-14995 Cross-site Scripting vulnerability in Wso2 products
The Management Console in WSO2 Application Server 5.3.0, WSO2 Business Process Server 3.6.0, WSO2 Business Rules Server 2.2.0, WSO2 Complex Event Processor 4.2.0, WSO2 Dashboard Server 2.0.0, WSO2 Data Analytics Server 3.1.0, WSO2 Data Services Server 3.5.1, and WSO2 Machine Learner 1.2.0 is affected by stored XSS.
network
low complexity
wso2 CWE-79
6.1
2017-09-21 CVE-2017-14651 Cross-site Scripting vulnerability in Wso2 products
WSO2 Data Analytics Server 3.1.0 has XSS in carbon/resources/add_collection_ajaxprocessor.jsp via the collectionName or parentPath parameter.
network
low complexity
wso2 CWE-79
4.8