WSO2 IS as Key Manager 5.7.0 allows web vulnerabilities

hugeously Overview :
An attacker can trick a privileged user while using WSO2 IS as Key Manager
Egra Affected Product(s) :
  • WSO2 IS as Key Manager 5.7.0
Vulnerability Details :
CVE ID : CVE-2019-18882
A reflected XSS attack could be performed in the dashboard user profile by sending an HTTP GET request with harmful request parameters. Further, a stored XSS attack could be performed in the download-userinfo. jag due to an improper Content-Type of the downloading content.
CVE ID : CVE-2019-18881
WSO2 IS as Key Manager 5.7.0 allows unauthenticated reflected XSS in the dashboard user profile.

Solution :

Apply the following patch based on your product version by following the instructions in the README file. If you have any questions, post them to security@wso2.com.

Please download the relevant patch based on the product you use following the matrix below. The patch can also be downloaded from http://wso2.com/security-patch-releases/.

Code Product Version Patch
IS KM WSO2 IS as Key Manager 5.7.0 WSO2-CARBON-PATCH-4.4.0-5019

 

Common Vulnerabilityies and Exposures

Contact us to get started

CVE-2024-5618 : PRUVASOFT INFORMATICS APINIZER MANAGEMENT CONSOLE PRIOR 2024.05.1 PERMISSION ASSIGNMENT

CVE-2024-5618 : PRUVASOFT INFORMATICS APINIZER MANAGEMENT CONSOLE PRIOR 2024.05.1 PERMISSION ASSIGNMENT

Description Incorrect Permission Assignment for Critical Resource vulnerability in PruvaSoft Informatics Apinizer Management Console allows Accessing Functionality Not Properly Constrained

CVE-2024-39907 : 1PANEL 1.10.9-TLS/1.10.10-TLS/1.10.11-TLS SQL INJECTION

CVE-2024-39907 : 1PANEL 1.10.9-TLS/1.10.10-TLS/1.10.11-TLS SQL INJECTION

Description 1Panel is a web-based linux server management control panel. There are many sql injections in the project, and some

CVE-2024-20401 : CISCO SECURE EMAIL CONTENT SCANNING/MESSAGE FILTERING ABSOLUTE PATH TRAVERSAL

CVE-2024-20401 : CISCO SECURE EMAIL CONTENT SCANNING/MESSAGE FILTERING ABSOLUTE PATH TRAVERSAL

Description A vulnerability in the content scanning and message filtering features of Cisco Secure Email Gateway could allow an unauthenticated,