The Management Console in certain WSO2 products allows XXE attacks during EventReceiver updates. This affects API Manager through 3.0.0, API Manager Analytics 2.2.0 and 2.5.0, API Microgateway 2.2.0, Enterprise Integrator 6.2.0 and 6.3.0, and Identity Server Analytics through 5.6.0.
Metrics
Affected Vendors & Products
References
History
No history.
MITRE
Status: PUBLISHED
Assigner: mitre
Published: 2020-08-21T19:05:53
Updated: 2024-08-04T15:19:08.739Z
Reserved: 2020-08-21T00:00:00
Link: CVE-2020-24591
Vulnrichment
No data.
NVD
Status : Modified
Published: 2020-08-21T20:15:11.093
Modified: 2024-11-21T05:15:06.473
Link: CVE-2020-24591
Redhat
No data.