PatchSiren

WSO2 CVE debriefs · Page 2

These pages are published after PatchSiren validates generated defensive summaries against stored public CVE and source evidence.

MEDIUM Wso2 CVE published 2017-02-17

CVE-2016-4315

CVE-2016-4315 is a cross-site request forgery issue in WSO2 Carbon 4.4.5 that can be abused to make a privileged user’s browser send a shutdown request to the server-admin/proxy_ajaxprocessor.jsp endpoint. The practical impact is denial of service: if a privileged session is tricked into issuing the action, the server can be shut down without the attacker needing direct authentication to the target.

MEDIUM Wso2 CVE published 2017-02-17

CVE-2016-4314

CVE-2016-4314 is a directory traversal vulnerability in the LogViewer Admin Service of WSO2 Carbon 4.4.5. According to the NVD description, a remote authenticated administrator can supply dot-dot sequences in the logFile parameter to downloadgz-ajaxprocessor.jsp and read arbitrary files. NVD assigns CWE-22 and a CVSS 3.0 score of 4.9 (MEDIUM).

HIGH Wso2 CVE published 2017-02-17

CVE-2016-4312

CVE-2016-4312 affects WSO2 Identity Server 5.1.0 and is a high-impact XML external entity (XXE) issue in the XACML flow feature. A crafted XACML request sent to entitlement/eval-policy-submit.jsp can trigger unsafe XML processing, which may allow an authenticated attacker with access to XACML features to read local files, cause denial of service, or perform server-side request forgery (SSRF). The vulnerab [truncated]

HIGH Wso2 CVE published 2017-02-17

CVE-2016-4311

CVE-2016-4311 is a high-severity cross-site request forgery (CSRF) issue in the XACML flow feature of WSO2 Identity Server 5.1.0. A remote attacker could abuse a logged-in privileged user’s session to submit unintended XACML-related requests through entitlement/eval-policy-submit.jsp. The NVD record rates the issue as CVSS 3.0 8.8 (AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H) and maps it to CWE-352.