XML External Entity (XXE) Vulnerability in WSO2 Management Console

XML External Entity (XXE) Vulnerability in WSO2 Management Console

CVE-2020-24591 · MEDIUM Severity

CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:N/A:H

The Management Console in certain WSO2 products allows XXE attacks during EventReceiver updates. This affects API Manager through 3.0.0, API Manager Analytics 2.2.0 and 2.5.0, API Microgateway 2.2.0, Enterprise Integrator 6.2.0 and 6.3.0, and Identity Server Analytics through 5.6.0.

Learn more about our Cis Benchmark Audit For Server Software.