ZeroHour

CVE-2020-13883

CVSS 3.1
6.7 medium
EPSS
<1%p54
Published
()
Modified
Description

In WSO2 API Manager 3.0.0 and earlier, WSO2 API Microgateway 2.2.0, and WSO2 IS as Key Manager 5.9.0 and earlier, Management Console allows XXE during addition or update of a Lifecycle.

Vendors
wso2
Products
api manager, api microgateway, identity server as key manager
Weakness
CWE-611
Vector
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:L/I:H/A:H

In the news

No ingested article mentions this CVE yet.