578
VMScore

CVE-2020-12719

Published: 08/05/2020 Updated: 14/05/2020
CVSS v2 Base Score: 6.5 | Impact Score: 6.4 | Exploitability Score: 8
CVSS v3 Base Score: 7.2 | Impact Score: 5.9 | Exploitability Score: 1.2
VMScore: 578
Vector: AV:N/AC:L/Au:S/C:P/I:P/A:P

Vulnerability Summary

XXE during an EventPublisher update can occur in Management Console in WSO2 API Manager 3.0.0 and previous versions, API Manager Analytics 2.5.0 and previous versions, API Microgateway 2.2.0, Enterprise Integrator 6.4.0 and previous versions, IS as Key Manager 5.9.0 and previous versions, Identity Server 5.9.0 and previous versions, and Identity Server Analytics 5.6.0 and previous versions.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

wso2 api manager

wso2 api manager analytics

wso2 api microgateway 2.2.0

wso2 enterprise integrator

wso2 identity server

wso2 identity server analytics

wso2 identity server as key manager