CVE-2023-6836
Severity CVSS v4.0:
Pending analysis
Type:
CWE-611
Improper Restriction of XML External Entity Reference ('XXE')
Publication date:
15/12/2023
Last modified:
19/12/2023
Description
Multiple WSO2 products have been identified as vulnerable due to an XML External Entity (XXE) attack abuses a widely available but rarely used feature of XML parsers to access sensitive information.
Impact
Base Score 3.x
7.50
Severity 3.x
HIGH
Vulnerable products and versions
| CPE | From | Up to |
|---|---|---|
| cpe:2.3:a:wso2:api_manager:*:*:*:*:*:*:*:* | 3.0.0 (including) | |
| cpe:2.3:a:wso2:api_manager_analytics:2.2.0:*:*:*:*:*:*:* | ||
| cpe:2.3:a:wso2:api_manager_analytics:2.5.0:*:*:*:*:*:*:* | ||
| cpe:2.3:a:wso2:api_microgateway:2.2.0:*:*:*:*:*:*:* | ||
| cpe:2.3:a:wso2:enterprise_integrator:*:*:*:*:*:*:*:* | 6.6.0 (including) | |
| cpe:2.3:a:wso2:identity_server_as_key_manager:5.0.0:*:*:*:*:*:*:* | ||
| cpe:2.3:a:wso2:identity_server_as_key_manager:5.6.0:*:*:*:*:*:*:* | ||
| cpe:2.3:a:wso2:identity_server_as_key_manager:5.7.0:*:*:*:*:*:*:* | ||
| cpe:2.3:a:wso2:identity_server_as_key_manager:5.9.0:*:*:*:*:*:*:* | ||
| cpe:2.3:a:wso2:identity_server:5.4.0:*:*:*:*:*:*:* | ||
| cpe:2.3:a:wso2:identity_server:5.4.1:*:*:*:*:*:*:* | ||
| cpe:2.3:a:wso2:identity_server:5.5.0:*:*:*:*:*:*:* | ||
| cpe:2.3:a:wso2:identity_server:5.6.0:*:*:*:*:*:*:* | ||
| cpe:2.3:a:wso2:micro_integrator:1.0.0:*:*:*:*:*:*:* |
To consult the complete list of CPE names with products and versions, see this page



