Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-hc9x-xmwh-8232

Опубликовано: 24 мая 2022
Источник: github
Github: Не прошло ревью
CVSS3: 6.5

Описание

The Management Console in certain WSO2 products allows XXE attacks during EventReceiver updates. This affects API Manager through 3.0.0, API Manager Analytics 2.2.0 and 2.5.0, API Microgateway 2.2.0, Enterprise Integrator 6.2.0 and 6.3.0, and Identity Server Analytics through 5.6.0.

The Management Console in certain WSO2 products allows XXE attacks during EventReceiver updates. This affects API Manager through 3.0.0, API Manager Analytics 2.2.0 and 2.5.0, API Microgateway 2.2.0, Enterprise Integrator 6.2.0 and 6.3.0, and Identity Server Analytics through 5.6.0.

EPSS

Процентиль: 60%
0.00403
Низкий

6.5 Medium

CVSS3

Дефекты

CWE-611
CWE-776

Связанные уязвимости

CVSS3: 6.5
nvd
больше 5 лет назад

The Management Console in certain WSO2 products allows XXE attacks during EventReceiver updates. This affects API Manager through 3.0.0, API Manager Analytics 2.2.0 and 2.5.0, API Microgateway 2.2.0, Enterprise Integrator 6.2.0 and 6.3.0, and Identity Server Analytics through 5.6.0.

EPSS

Процентиль: 60%
0.00403
Низкий

6.5 Medium

CVSS3

Дефекты

CWE-611
CWE-776