← Back to CVE List
Vulnerability Intelligence Report

CVE-2022-29548

A reflected XSS issue exists in the Management Console of several WSO2 products. This affects API Manager 2.2.0, 2.5.0, 2.6.0, 3.0.0, 3.1.0, 3.2.0, and 4.0.0; API Manager Analytics 2.2.0, 2.5.0, and 2.6.0; API Microgateway 2.2.0; Data Analytics Server 3.2.0; Enterprise Integrator 6.2.0, 6.3.0, 6.4.0, 6.5.0, and 6.6.0; IS as Key Manager 5.5.0, 5.6.0, 5.7.0, 5.9.0, and 5.10.0; Identity Server 5.5.0, 5.6.0, 5.7.0, 5.9.0, 5.10.0, and 5.11.0; Identity Server Analytics 5.5.0 and 5.6.0; and WSO2 Micro Integrator 1.0.0.

Nuclei Template
CVSS Base Score
4.6
MEDIUM
Exploitability:2.1
Impact Score:2.6
EPSS Probability:40.48%
Executive Threat Verdict
Evaluating...
Evaluating Threat Landscape...
Assessing known weaponization, exploitation telemetry, and federal advisories.
Attack Surface
—
Authentication
—
Weaponization
—
SSVC Action
—

Affected Products & Versions

Vendor Product Affected Versions
wso2 api_manager 2.2.0, 2.5.0, 2.6.0, 3.0.0, 3.1.0, 3.2.0, 4.0.0
wso2 api_manager_analytics 2.2.0, 2.5.0, 2.6.0
wso2 api_microgateway 2.2.0
wso2 data_analytics_server 3.2.0
wso2 enterprise_integrator 6.2.0, 6.3.0, 6.4.0, 6.5.0, 6.6.0
wso2 identity_server 5.5.0, 5.6.0, 5.7.0, 5.9.0, 5.10.0, 5.11.0
wso2 identity_server_analytics 5.5.0, 5.6.0
wso2 identity_server_as_key_manager 5.5.0, 5.6.0, 5.7.0, 5.9.0, 5.10.0
wso2 micro_integrator 1.0.0

References & Technical Advisories

No reference links found.

Threat Intelligence Signals

Nuclei Template
SCANNER AVAILABLE
EPSS Score
40.481%

Identity & Timeline

StatusPUBLISHED
Assigning AuthorityMITRE Corporation · N/A · USA
Reserved2022-04-21T00:00:00
Published2022-04-21T00:00:00
Last Updated2024-08-03T06:26:06

LINK COPIED TO CLIPBOARD