Not a U.S. government website. NDD is an independent vulnerability database by Volerion and is not affiliated with or endorsed by NIST or NVD.
CVE-2017-14651 Details
Description
WSO2 Data Analytics Server 3.1.0 has XSS in carbon/resources/add_collection_ajaxprocessor.jsp via the collectionName or parentPath parameter.
Metrics
CVSS 4.0 Severity and Vector Strings:
No CVSS 4.0 data is available for this CVE.
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
No SSVC data is available for this CVE.
References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| https://cybersecurityworks.com/zerodays/cve-2017-14651-wso2.html | CVE | ExploitThird Party Advisory |
| https://docs.wso2.com/display/Security/Security+Advisory+WSO2-2017-0265 | CVE | PatchVendor Advisory |
| https://github.com/cybersecurityworks/Disclosed/issues/15 | CVE | ExploitTechnical DescriptionThird Party Advisory |
| https://cybersecurityworks.com/zerodays/cve-2017-14651-wso2.html | [email protected] | ExploitThird Party Advisory |
| https://docs.wso2.com/display/Security/Security+Advisory+WSO2-2017-0265 | [email protected] | PatchVendor Advisory |
| https://github.com/cybersecurityworks/Disclosed/issues/15 | [email protected] | ExploitTechnical DescriptionThird Party Advisory |
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-79 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') | [email protected] |
Affected Products
| Product | Versions |
|---|---|
| wso2 api manager | 2.1.0 |
CPE
Remediation
| |
| wso2 app manager | 1.2.0 |
CPE
Remediation
| |
| wso2 application server | 5.3.0 |
CPE
Remediation
| |
| wso2 business process server | 3.6.0 |
CPE
Remediation
| |
| wso2 business rules server | 2.2.0 |
CPE
Remediation
| |
| wso2 complex event processor | 4.2.0 |
CPE
Remediation
| |
| wso2 dashboard server | 2.0.0 |
CPE
Remediation
| |
| wso2 data analytics server | 3.1.0 |
CPE
Remediation
| |
| wso2 data services server | 3.5.1 |
CPE
Remediation
| |
| wso2 enterprise integrator | 6.1.1 |
CPE
Remediation
| |
| wso2 enterprise mobility manager | 2.2.0 |
CPE
Remediation
| |
| wso2 governance registry | 5.4.0 |
CPE
Remediation
| |
| wso2 identity server | 5.3.0 |
CPE
Remediation
| |
| wso2 iot server | 3.0.0 |
CPE
Remediation
| |
| wso2 machine learner | 1.2.0 |
CPE
Remediation
| |
| wso2 message broker | 3.2.0 |
CPE
Remediation
| |
| wso2 storage server | 1.5.0 |
CPE
Remediation
| |
Change History
7 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Jun 17, 2026 | CVE Modified | [email protected] |
| May 13, 2026 | CVE Status Change | [email protected] |
| Nov 21, 2024 | CVE Modified | CVE |
| May 14, 2024 | CVE Modified | [email protected] |
| Nov 9, 2020 | Modified Analysis | [email protected] |
| Oct 29, 2020 | CVE Modified | [email protected] |
| Sep 28, 2017 | Initial Analysis | [email protected] |