CVE-2017-14651: WSO2 API Manager
Medium severity, CVSS 4.8. EPSS: 3.8% chance of exploitation in the next 30 days.
WSO2 Data Analytics Server 3.1.0 has XSS in carbon/resources/add_collection_ajaxprocessor.jsp via the collectionName or parentPath parameter.
Affected products
- WSO2 API Manager: version 2.1.0 only
- WSO2 App Manager: version 1.2.0 only
- WSO2 Application Server: version 5.3.0 only
- WSO2 Business Process Server: version 3.6.0 only
- WSO2 Business Rules Server: version 2.2.0 only
- WSO2 Complex Event Processor: version 4.2.0 only
- WSO2 Dashboard Server: version 2.0.0 only
- WSO2 Data Analytics Server: version 3.1.0 only
- WSO2 Data Services Server: version 3.5.1 only
- WSO2 Enterprise Integrator: version 6.1.1 only
- WSO2 Enterprise Mobility Manager: version 2.2.0 only
- WSO2 Governance Registry: version 5.4.0 only
- WSO2 Identity Server: version 5.3.0 only
- WSO2 IoT Server: version 3.0.0 only
- WSO2 Machine Learner: version 1.2.0 only
- WSO2 Message Broker: version 3.2.0 only
- WSO2 Storage Server: version 1.5.0 only
Published 2017-09-21. Last modified 2026-06-17.