CVE-2020-24591

The Management Console in certain WSO2 products allows XXE attacks during EventReceiver updates. This affects API Manager through 3.0.0, API Manager Analytics 2.2.0 and 2.5.0, API Microgateway 2.2.0, Enterprise Integrator 6.2.0 and 6.3.0, and Identity Server Analytics through 5.6.0.
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTNIST
6.5 MEDIUM
NETWORK
LOW
HIGH
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:N/A:H
mitreCNA
6.5 MEDIUM
NETWORK
LOW
HIGH
CVSS:3.1/AC:L/AV:N/A:H/C:H/I:N/PR:H/S:U/UI:N
CVEADP
---
---
Base Score
CVSS 3.x
EPSS Score
Percentile: 59%
VendorProductVersion
wso2api_manager
𝑥
≤ 3.0.0
wso2api_manager_analytics
2.2.0
wso2api_manager_analytics
2.5.0
wso2api_microgateway
2.2.0
wso2enterprise_integrator
6.2.0
wso2enterprise_integrator
6.3.0
wso2identity_server_analytics
𝑥
≤ 5.6.0
𝑥
= Vulnerable software versions