Showing 3 vulnerabilities on this page for WSO2 IS as Key Manager

Signals CISA KEV Ransomware Nuclei
WSO2 vulnerability results
VulnerabilityTitle and contextCVSSEPSSPoCsSignalsSTIX action

WSO2 Registry Stored Cross Site Scripting (XSS) vulnerability

Multiple WSO2 products have been identified as vulnerable due to improper output encoding, a Stored Cross Site Scripting (XSS) attack can be carried out by an attacker injecting a malicious payload into the Registry feature of the Management Console.

CWE-79Dec 18, 2023
CVSS4.8v3.1EPSS0.406%PoCs0SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templatesSTIX

Reflected XSS vulnerability can be exploited by tampering a request parameter in Authentication Endpoint. This can be performed in both authenticated and unauthenticated requests.

CWE-79Dec 15, 2023
CVSS6.1v3.1EPSS0.433%PoCs0SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templatesSTIX

WSO2 products vulnerable to XML External Entity attack

Multiple WSO2 products have been identified as vulnerable due to an XML External Entity (XXE) attack abuses a widely available but rarely used feature of XML parsers to access sensitive information.

CWE-611Dec 15, 2023
CVSS4.6v3.1EPSS0.482%PoCs0SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templatesSTIX