CVE-2023-6836
15.12.2023, 10:15
Multiple WSO2 products have been identified as vulnerable due to an XML External Entity (XXE) attack abuses a widely available but rarely used feature of XML parsers to access sensitive information.Enginsight
Vendor | Product | Version |
---|---|---|
wso2 | api_manager | 𝑥 ≤ 3.0.0 |
wso2 | api_manager_analytics | 2.2.0 |
wso2 | api_manager_analytics | 2.5.0 |
wso2 | api_microgateway | 2.2.0 |
wso2 | enterprise_integrator | 𝑥 ≤ 6.6.0 |
wso2 | identity_server_as_key_manager | 5.0.0 |
wso2 | identity_server_as_key_manager | 5.6.0 |
wso2 | identity_server_as_key_manager | 5.7.0 |
wso2 | identity_server_as_key_manager | 5.9.0 |
wso2 | identity_server | 5.4.0 |
wso2 | identity_server | 5.4.1 |
wso2 | identity_server | 5.5.0 |
wso2 | identity_server | 5.6.0 |
wso2 | micro_integrator | 1.0.0 |
𝑥
= Vulnerable software versions