In a few clicks we can analyze your entire application and see what components are vulnerable in your application, and suggest you quick fixes.
Test your applicationsLearn about Arbitrary Code Injection vulnerabilities in an interactive lesson.
Start learningUpgrade org.apache.synapse:synapse-extensions to version 4.0.0-wso2v255 or higher.
org.apache.synapse:synapse-extensions is an Apache Synapse - Extensions
Affected versions of this package are vulnerable to Arbitrary Code Injection due to a lack of controls on the GraalJS and NashornJS Script Mediator engines. An attacker can execute arbitrary code with elevated privileges by submitting crafted scripts to the integration runtime environment. This is only exploitable if the attacker is an authenticated user with administrator or API creator privileges, depending on the product configuration.