Skip to end of metadata
Go to start of metadata

Published: 02nd December 2019

Severity: Medium

CVSS Score: 5.8 (CVSS:3.0/AV:N/AC:H/PR:N/UI:R/S:C/C:L/I:L/A:L)


WSO2 IS as Key Manager

WSO2 Identity Server


WSO2 Carbon Management Console retrieves several external JavaScript libraries via an unencrypted HTTP channel.


Several JavaScript libraries used by the XACML entitlement user interfaces of WSO2 Carbon Management Console are retrieved from external sources over unencrypted HTTP channel.


A malicious entity may intercept the unencrypted HTTP request used to retrieve the JavaScript content and/or alter the unencrypted HTTP response to include malicious content, in combination with other attack vectors such as man-in-the-middle attacks.


Upgrade the WSO2 IS as Key Manager to 5.9.0 and WSO2 Identity Server to 5.9.0 or higher released version which is not affected by this vulnerability.  If you have any questions, post them to [email protected].

Note: If you are a WSO2 customer with Support Subscription, please use WSO2 Update Manager (WUM) updates in order to apply the fix to the affected versions.

  • No labels