ZeroHour

CVE-2023-6836

CVSS 3.1
7.5 high
EPSS
<1%p40
Published
()
Modified
Description

Multiple WSO2 products have been identified as vulnerable due to an XML External Entity (XXE) attack abuses a widely available but rarely used feature of XML parsers to access sensitive information.

Vendors
wso2
Products
api manager, api manager analytics, api microgateway, enterprise integrator, identity server as key manager, identity server, micro integrator
Weakness
CWE-611
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N

In the news

No ingested article mentions this CVE yet.