XXE during an EventPublisher update can occur in Management Console in WSO2 API Manager 3.0.0 and earlier, API Manager Analytics 2.5.0 and earlier, API Microgateway 2.2.0, Enterprise Integrator 6.4.0 and earlier, IS as Key Manager 5.9.0 and earlier, Identity Server 5.9.0 and earlier, and Identity Server Analytics 5.6.0 and earlier.
References
Link | Resource |
---|---|
https://docs.wso2.com/display/Security/Security+Advisory+WSO2-2019-0665 | Vendor Advisory |
Configurations
Configuration 1 (hide)
|
History
No history.
Information
Published : 2020-05-08 00:15
Updated : 2024-02-28 17:47
NVD link : CVE-2020-12719
Mitre link : CVE-2020-12719
CVE.ORG link : CVE-2020-12719
JSON object : View
Products Affected
wso2
- api_manager
- enterprise_integrator
- identity_server
- identity_server_as_key_manager
- api_microgateway
- api_manager_analytics
- identity_server_analytics
CWE
CWE-611
Improper Restriction of XML External Entity Reference