6.7
CVSSv3

CVE-2020-13883

Published: 06/06/2020 Updated: 10/06/2020
CVSS v2 Base Score: 6.5 | Impact Score: 6.4 | Exploitability Score: 8
CVSS v3 Base Score: 6.7 | Impact Score: 5.5 | Exploitability Score: 1.2
VMScore: 578
Vector: AV:N/AC:L/Au:S/C:P/I:P/A:P

Vulnerability Summary

In WSO2 API Manager 3.0.0 and previous versions, WSO2 API Microgateway 2.2.0, and WSO2 IS as Key Manager 5.9.0 and previous versions, Management Console allows XXE during addition or update of a Lifecycle.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

wso2 api manager

wso2 api microgateway 2.2.0

wso2 identity server as key manager