CVE-2025-2905

Severity CVSS v4.0:
Pending analysis
Type:
CWE-611 Improper Restriction of XML External Entity Reference ('XXE')
Publication date:
05/05/2025
Last modified:
16/10/2025

Description

Due to the improper configuration of XML parser, user-supplied XML is parsed without applying sufficient restrictions, enabling XML External Entity (XXE) resolution in multiple WSO2 Products.<br /> <br /> A successful XXE attack could allow a remote, unauthenticated attacker to:<br /> * Read sensitive files from the server’s filesystem.<br /> * Perform denial-of-service (DoS) attacks, which can render the affected service unavailable.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:wso2:api_manager:*:*:*:*:*:*:*:* 2.0.0 (including)