CVE-2019-6512

Severity CVSS v4.0:
Pending analysis
Type:
CWE-918 Server-Side Request Forgery (SSRF)
Publication date:
14/05/2019
Last modified:
30/05/2025

Description

An issue was discovered in WSO2 API Manager 2.6.0. It is possible to force the application to perform requests to the internal workstation (SSRF port-scanning), other adjacent workstations (SSRF network scanning), or to enumerate files because of the existence of the file:// wrapper.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:wso2:api_manager:2.6.0:*:*:*:*:*:*:*