Wso2

Enterprise Integrator

23 vulnerabilities found.

Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
  • EPSS 0.28%
  • Published 26.09.2025 09:15:31
  • Last modified 06.10.2025 13:43:41

An arbitrary file upload vulnerability exists in multiple WSO2 products due to improper validation of user-supplied filenames in the BPEL uploader SOAP service endpoint. A malicious actor with administrative privileges can upload arbitrary files to a...

  • EPSS 0.04%
  • Published 23.06.2025 08:47:55
  • Last modified 06.10.2025 13:35:40

An incorrect authorization vulnerability exists in multiple WSO2 products that allows unauthorized access to versioned files stored in the registry. Due to flawed authorization logic, a malicious actor with access to the management console can exploi...

  • EPSS 0.04%
  • Published 02.06.2025 16:48:12
  • Last modified 06.10.2025 13:51:36

A reflected cross-site scripting (XSS) vulnerability exists in multiple WSO2 products due to insufficient output encoding in error messages generated by the JDBC user store connection validation request. A malicious actor can inject a specially craft...

  • EPSS 0.04%
  • Published 02.06.2025 16:44:28
  • Last modified 06.10.2025 13:48:27

A stored cross-site scripting (XSS) vulnerability exists in the Management Console of multiple WSO2 products due to insufficient input validation in the Rich Text Editor within the registry section. To exploit this vulnerability, a malicious actor mu...

  • EPSS 0.1%
  • Published 02.06.2025 16:42:19
  • Last modified 02.06.2025 17:32:17

An arbitrary file upload vulnerability exists in multiple WSO2 products due to improper validation of user input in SOAP admin services. A malicious actor with administrative privileges can upload an arbitrary file to a user-controlled location on th...

  • EPSS 0.04%
  • Published 27.02.2025 07:15:32
  • Last modified 06.10.2025 13:55:23

A Cross-Site Request Forgery (CSRF) vulnerability exists in the management console of WSO2 Enterprise Integrator 6.6.0 due to the absence of CSRF token validation. This flaw allows attackers to craft malicious requests that can trigger state-changing...

  • EPSS 0.35%
  • Published 18.12.2023 09:15:05
  • Last modified 21.11.2024 08:44:49

Multiple WSO2 products have been identified as vulnerable due to improper output encoding, a Stored Cross Site Scripting (XSS) attack can be carried out by an attacker injecting a malicious payload into the Registry feature of the Management Console....

  • EPSS 0.17%
  • Published 15.12.2023 10:15:09
  • Last modified 21.11.2024 08:44:38

Multiple WSO2 products have been identified as vulnerable due to an XML External Entity (XXE) attack abuses a widely available but rarely used feature of XML parsers to access sensitive information.

  • EPSS 2.1%
  • Published 09.09.2022 17:15:08
  • Last modified 21.11.2024 07:18:17

An issue was discovered in WSO2 Enterprise Integrator 6.4.0. A Reflected Cross-Site Scripting (XSS) vulnerability has been identified in the Management Console under /carbon/ndatasource/validateconnection/ajaxprocessor.jsp via the driver parameter. S...

  • EPSS 0.23%
  • Published 09.09.2022 17:15:08
  • Last modified 21.11.2024 07:18:17

An issue was discovered in WSO2 Enterprise Integrator 6.4.0. A Reflected Cross-Site Scripting (XSS) vulnerability has been identified in the Management Console under /carbon/mediation_secure_vault/properties/ajaxprocessor.jsp via the name parameter. ...