CVE-2016-4314: WSO2 Carbon
Medium severity, CVSS 4.9. EPSS: 12.4% chance of exploitation in the next 30 days.
Directory traversal vulnerability in the LogViewer Admin Service in WSO2 Carbon 4.4.5 allows remote authenticated administrators to read arbitrary files via a .. (dot dot) in the logFile parameter to downloadgz-ajaxprocessor.jsp.
Affected products
- WSO2 Carbon: version 4.4.5 only
Published 2017-02-17. Last modified 2026-06-17.