Multiple WSO2 products have been identified as vulnerable due to improper output encoding, a Stored Cross Site Scripting (XSS) attack can be carried out by an attacker injecting a malicious payload into the Registry feature of the Management Console.
{
"unresolved_ranges": [
{
"vendor_product": "wso2:api_microgateway",
"extracted_events": [
{
"last_affected": "2.2.0"
}
],
"cpes": [
"cpe:2.3:a:wso2:api_microgateway:2.2.0:*:*:*:*:*:*:*"
],
"source": "CPE_FIELD"
},
{
"source": "CPE_FIELD",
"extracted_events": [
{
"last_affected": "3.2.0"
}
],
"cpes": [
"cpe:2.3:a:wso2:data_analytics_server:3.2.0:*:*:*:*:*:*:*"
],
"vendor_product": "wso2:data_analytics_server"
},
{
"source": "CPE_FIELD",
"extracted_events": [
{
"last_affected": "6.1.0"
},
{
"last_affected": "6.1.1"
},
{
"last_affected": "6.2.0"
},
{
"last_affected": "6.3.0"
},
{
"last_affected": "6.4.0"
},
{
"last_affected": "6.5.0"
},
{
"last_affected": "6.6.0"
}
],
"cpes": [
"cpe:2.3:a:wso2:enterprise_integrator:6.1.0:*:*:*:*:*:*:*",
"cpe:2.3:a:wso2:enterprise_integrator:6.1.1:*:*:*:*:*:*:*",
"cpe:2.3:a:wso2:enterprise_integrator:6.2.0:*:*:*:*:*:*:*",
"cpe:2.3:a:wso2:enterprise_integrator:6.3.0:*:*:*:*:*:*:*",
"cpe:2.3:a:wso2:enterprise_integrator:6.4.0:*:*:*:*:*:*:*",
"cpe:2.3:a:wso2:enterprise_integrator:6.5.0:*:*:*:*:*:*:*",
"cpe:2.3:a:wso2:enterprise_integrator:6.6.0:*:*:*:*:*:*:*"
],
"vendor_product": "wso2:enterprise_integrator"
},
{
"source": "CPE_FIELD",
"extracted_events": [
{
"last_affected": "5.4.0"
},
{
"last_affected": "5.4.1"
},
{
"last_affected": "5.5.0"
},
{
"last_affected": "5.6.0"
},
{
"last_affected": "5.7.0"
},
{
"last_affected": "5.8.0"
},
{
"last_affected": "5.9.0"
},
{
"last_affected": "5.10.0"
}
],
"cpes": [
"cpe:2.3:a:wso2:identity_server:5.10.0:*:*:*:*:*:*:*",
"cpe:2.3:a:wso2:identity_server:5.4.0:*:*:*:*:*:*:*",
"cpe:2.3:a:wso2:identity_server:5.4.1:*:*:*:*:*:*:*",
"cpe:2.3:a:wso2:identity_server:5.5.0:*:*:*:*:*:*:*",
"cpe:2.3:a:wso2:identity_server:5.6.0:*:*:*:*:*:*:*",
"cpe:2.3:a:wso2:identity_server:5.7.0:*:*:*:*:*:*:*",
"cpe:2.3:a:wso2:identity_server:5.8.0:*:*:*:*:*:*:*",
"cpe:2.3:a:wso2:identity_server:5.9.0:*:*:*:*:*:*:*"
],
"vendor_product": "wso2:identity_server"
},
{
"source": "CPE_FIELD",
"extracted_events": [
{
"last_affected": "5.5.0"
},
{
"last_affected": "5.6.0"
},
{
"last_affected": "5.7.0"
},
{
"last_affected": "5.9.0"
},
{
"last_affected": "5.10.0"
}
],
"cpes": [
"cpe:2.3:a:wso2:identity_server_as_key_manager:5.10.0:*:*:*:*:*:*:*",
"cpe:2.3:a:wso2:identity_server_as_key_manager:5.5.0:*:*:*:*:*:*:*",
"cpe:2.3:a:wso2:identity_server_as_key_manager:5.6.0:*:*:*:*:*:*:*",
"cpe:2.3:a:wso2:identity_server_as_key_manager:5.7.0:*:*:*:*:*:*:*",
"cpe:2.3:a:wso2:identity_server_as_key_manager:5.9.0:*:*:*:*:*:*:*"
],
"vendor_product": "wso2:identity_server_as_key_manager"
},
{
"vendor_product": "wso2:message_broker",
"extracted_events": [
{
"last_affected": "3.2.0"
}
],
"cpes": [
"cpe:2.3:a:wso2:message_broker:3.2.0:*:*:*:*:*:*:*"
],
"source": "CPE_FIELD"
}
]
}{
"source": "CPE_FIELD",
"extracted_events": [
{
"introduced": "0"
},
{
"last_affected": "5.4.0"
},
{
"last_affected": "5.4.1"
},
{
"last_affected": "5.5.0"
},
{
"last_affected": "5.6.0"
}
],
"cpe": [
"cpe:2.3:a:wso2:identity_server_analytics:5.4.0:*:*:*:*:*:*:*",
"cpe:2.3:a:wso2:identity_server_analytics:5.4.1:*:*:*:*:*:*:*",
"cpe:2.3:a:wso2:identity_server_analytics:5.5.0:*:*:*:*:*:*:*",
"cpe:2.3:a:wso2:identity_server_analytics:5.6.0:*:*:*:*:*:*:*"
]
}{
"cpe": [
"cpe:2.3:a:wso2:api_manager_analytics:2.2.0:*:*:*:*:*:*:*",
"cpe:2.3:a:wso2:api_manager_analytics:2.5.0:*:*:*:*:*:*:*"
],
"extracted_events": [
{
"introduced": "0"
},
{
"last_affected": "2.2.0"
},
{
"last_affected": "2.5.0"
}
],
"source": "CPE_FIELD"
}{
"cpe": [
"cpe:2.3:a:wso2:api_manager:2.2.0:*:*:*:*:*:*:*",
"cpe:2.3:a:wso2:api_manager:2.5.0:*:*:*:*:*:*:*",
"cpe:2.3:a:wso2:api_manager:2.6.0:*:*:*:*:*:*:*",
"cpe:2.3:a:wso2:api_manager:3.0.0:*:*:*:*:*:*:*",
"cpe:2.3:a:wso2:api_manager:3.1.0:*:*:*:*:*:*:*",
"cpe:2.3:a:wso2:api_manager:3.2.0:*:*:*:*:*:*:*"
],
"extracted_events": [
{
"introduced": "0"
},
{
"last_affected": "2.2.0"
},
{
"last_affected": "2.5.0"
},
{
"last_affected": "2.6.0"
},
{
"last_affected": "3.0.0"
},
{
"last_affected": "3.1.0"
},
{
"last_affected": "3.2.0"
}
],
"source": "CPE_FIELD"
}