CVE-2020-13883
06.06.2020, 19:15
In WSO2 API Manager 3.0.0 and earlier, WSO2 API Microgateway 2.2.0, and WSO2 IS as Key Manager 5.9.0 and earlier, Management Console allows XXE during addition or update of a Lifecycle.Enginsight
Vendor | Product | Version |
---|---|---|
wso2 | api_manager | 𝑥 ≤ 3.0.0 |
wso2 | api_microgateway | 2.2.0 |
wso2 | identity_server_as_key_manager | 𝑥 ≤ 5.9.0 |
𝑥
= Vulnerable software versions