ZeroHour

CVE-2020-12719

CVSS 3.1
7.2 high
EPSS
1%p62
Published
()
Modified
Description

XXE during an EventPublisher update can occur in Management Console in WSO2 API Manager 3.0.0 and earlier, API Manager Analytics 2.5.0 and earlier, API Microgateway 2.2.0, Enterprise Integrator 6.4.0 and earlier, IS as Key Manager 5.9.0 and earlier, Identity Server 5.9.0 and earlier, and Identity Server Analytics 5.6.0 and earlier.

Vendors
wso2
Products
api manager, api manager analytics, api microgateway, enterprise integrator, identity server, identity server analytics, identity server as key manager
Weakness
CWE-611
Vector
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H

In the news

No ingested article mentions this CVE yet.