CVE-2020-24591

EUVD-2020-17308
The Management Console in certain WSO2 products allows XXE attacks during EventReceiver updates. This affects API Manager through 3.0.0, API Manager Analytics 2.2.0 and 2.5.0, API Microgateway 2.2.0, Enterprise Integrator 6.2.0 and 6.3.0, and Identity Server Analytics through 5.6.0.
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTPrimary
6.5 MEDIUM
NETWORK
LOW
HIGH
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:N/A:H
mitreCNA
6.5 MEDIUM
NETWORK
LOW
HIGH
CVSS:3.1/AC:L/AV:N/A:H/C:H/I:N/PR:H/S:U/UI:N
Base Score
CVSS 3.x
EPSS Score
Percentile: 60%
Affected Products (NVD)
VendorProductVersion
wso2api_manager
𝑥
≤ 3.0.0
wso2api_manager_analytics
2.2.0
wso2api_manager_analytics
2.5.0
wso2api_microgateway
2.2.0
wso2enterprise_integrator
6.2.0
wso2enterprise_integrator
6.3.0
wso2identity_server_analytics
𝑥
≤ 5.6.0
𝑥
= Vulnerable software versions