S4E just found a high-severity finding from top 10 tcp port service scan
PlatformPlansPartners
Resources
ToolsBlogDocs
Sign Up →
medium·Product Based Web Vulnerabilities·Updated Jan 3, 2024

CVE-2017-14651 Scanner

CVE-2017-14651 scanner - Cross-Site Scripting (XSS) vulnerability in WSO2 Data Analytics Server

Est. Time~10 seconds
Scan TypeSingle Scan
Targetsurl
CostFree
3.4k
Times Used
continuous scan runs
4.1k
Continuously Checked
assets under CS
0
Vulnerabilities Found
confirmed findings
References
CVECVE-2017-14651
4.8
CVSS

WSO2 Data Analytics Server 3.1.0 has XSS in carbon/resources/add_collection_ajaxprocessor.jsp via the collectionName or parentPath parameter.

Attack Vector
-
Privileges Req.
-
User Interaction
-
Affected
n/aby n/a
n/a
Updated Aug 22, 2026View on NVD →
Detail

WSO2 Data Analytics Server is a powerful tool used to analyze large amounts of data and extract valuable insights that can help businesses make informed decisions. It is an open-source platform that offers real-time data processing, analytics, and visualization features. WSO2 Data Analytics Server is widely used across industries such as healthcare, finance, retail, and telecommunications.

One of the vulnerabilities detected in WSO2 Data Analytics Server is CVE-2017-14651. This vulnerability allows an attacker to execute cross-site scripting (XSS) attacks via the collectionName or parentPath parameter in carbon/resources/add_collection_ajaxprocessor.jsp. This vulnerability can result in unauthorized access to sensitive data, and can also lead to attackers gaining control of the server or system.

Exploiting this vulnerability can give attackers access to personal and confidential information such as customer data, financial information, and sensitive business data. Additionally, hackers can use this exploit to gain unauthorized access to the system and cause significant damage, resulting in downtime and loss of revenue for the business.

In conclusion, vulnerabilities such as CVE-2017-14651 can have severe consequences if left unaddressed. It is crucial to take preventive measures to protect against these attacks, such as installing security updates and using a web application firewall. With s4e.io's pro features, businesses can quickly and easily identify vulnerabilities in their digital assets and take appropriate measures to mitigate risks. Protecting against vulnerabilities is essential to ensuring the safety and security of valuable data.

 

REFERENCES

Solution Advice

To protect against this vulnerability, WSO2 has provided the following precautions:

  • Install the latest security updates for WSO2 Data Analytics Server.
  • Disable the collectionName and parentPath parameters in carbon/resources/add_collection_ajaxprocessor.jsp.
  • Restrict access to the WSO2 Data Analytics Server to authorized personnel only.
  • Regularly monitor server logs to detect any suspicious activity.
  • Use a web application firewall to prevent XSS attacks.

Get AI-powered remediation steps tailored to your asset.

Try AI Solutions →

Check your infrastructure.
Right now.

11,000+ scanners. Free to start. No credit card required.

CVE-2017-14651 scanner - Cross-Site Scripting (XSS) vulnerability in WSO2 Data Analytics Server | S4E