XXE Vulnerability in WSO2 API Manager and Related Products
CVE-2020-12719

8.7HIGH

What is CVE-2020-12719?

An XML External Entity (XXE) vulnerability exists in the management console of WSO2 API Manager and several related products. This flaw allows attackers to exploit security weaknesses during EventPublisher updates, potentially exposing sensitive data or leading to other forms of exploits. Businesses using affected versions should prioritize timely updates and security measures to mitigate this risk.

References

CVSS V3.1

Score:
8.7
Severity:
HIGH
Confidentiality:
High
Integrity:
None
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
High
User Interaction:
None
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.