CVE-2020-12719

Severity CVSS v4.0:
Pending analysis
Type:
CWE-611 Improper Restriction of XML External Entity Reference ('XXE')
Publication date:
08/05/2020
Last modified:
14/05/2020

Description

XXE during an EventPublisher update can occur in Management Console in WSO2 API Manager 3.0.0 and earlier, API Manager Analytics 2.5.0 and earlier, API Microgateway 2.2.0, Enterprise Integrator 6.4.0 and earlier, IS as Key Manager 5.9.0 and earlier, Identity Server 5.9.0 and earlier, and Identity Server Analytics 5.6.0 and earlier.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:wso2:api_manager:*:*:*:*:*:*:*:* 3.0.0 (including)
cpe:2.3:a:wso2:api_manager_analytics:*:*:*:*:*:*:*:* 2.5.0 (including)
cpe:2.3:a:wso2:api_microgateway:2.2.0:*:*:*:*:*:*:*
cpe:2.3:a:wso2:enterprise_integrator:*:*:*:*:*:*:*:* 6.4.0 (including)
cpe:2.3:a:wso2:identity_server:*:*:*:*:*:*:*:* 5.9.0 (including)
cpe:2.3:a:wso2:identity_server_analytics:*:*:*:*:*:*:*:* 5.6.0 (including)
cpe:2.3:a:wso2:identity_server_as_key_manager:*:*:*:*:*:*:*:* 5.9.0 (including)