XXE during an EventPublisher update can occur in Management Console in WSO2 API Manager 3.0.0 and earlier, API Manager Analytics 2.5.0 and earlier, API Microgateway 2.2.0, Enterprise Integrator 6.4.0 and earlier, IS as Key Manager 5.9.0 and earlier, Identity Server 5.9.0 and earlier, and Identity Server Analytics 5.6.0 and earlier.
References
Link | Resource |
---|---|
https://docs.wso2.com/display/Security/Security+Advisory+WSO2-2019-0665 | Vendor Advisory |
Configurations
Configuration 1 (hide)
|
Information
Published : 2020-05-07 17:15
Updated : 2020-05-14 08:58
NVD link : CVE-2020-12719
Mitre link : CVE-2020-12719
JSON object : View
CWE
CWE-611
Improper Restriction of XML External Entity Reference
Products Affected
wso2
- api_manager
- api_manager_analytics
- api_microgateway
- identity_server_as_key_manager
- identity_server
- enterprise_integrator
- identity_server_analytics