570
VMScore

CVE-2021-42646

Published: 11/05/2022 Updated: 11/01/2024
CVSS v2 Base Score: 6.4 | Impact Score: 4.9 | Exploitability Score: 10
CVSS v3 Base Score: 9.1 | Impact Score: 5.2 | Exploitability Score: 3.9
VMScore: 570
Vector: AV:N/AC:L/Au:N/C:P/I:N/A:P

Vulnerability Summary

XML External Entity (XXE) vulnerability in the file based service provider creation feature of the Management Console in WSO2 API Manager 2.6.0, 3.0.0, 3.1.0, 3.2.0, and 4.0.0; and WSO2 IS as Key Manager 5.7.0, 5.9.0, and 5.10.0; and WSO2 Identity Server 5.7.0, 5.8.0, 5.9.0, 5.10.0, and 5.11.0. Allows malicious users to gain read access to sensitive information or cause a denial of service via crafted GET requests.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

wso2 api manager 2.6.0

wso2 identity server 5.7.0

wso2 identity server as key manager 5.7.0

wso2 identity server 5.8.0

wso2 api manager 3.0.0

wso2 api manager 3.1.0

wso2 identity server as key manager 5.9.0

wso2 identity server as key manager 5.10.0

wso2 identity server 5.11.0

wso2 api manager 4.0.0

wso2 api manager 3.2.0

wso2 identity server 5.9.0

wso2 identity server 5.10.0