CVE-2016-4314: WSO2 Carbon

Medium severity, CVSS 4.9. EPSS: 12.4% chance of exploitation in the next 30 days.

Directory traversal vulnerability in the LogViewer Admin Service in WSO2 Carbon 4.4.5 allows remote authenticated administrators to read arbitrary files via a .. (dot dot) in the logFile parameter to downloadgz-ajaxprocessor.jsp.

Affected products

  • WSO2 Carbon: version 4.4.5 only

Published 2017-02-17. Last modified 2026-06-17.