NA

CVE-2023-6836

Published: 15/12/2023 Updated: 19/12/2023
CVSS v3 Base Score: 7.5 | Impact Score: 3.6 | Exploitability Score: 3.9
VMScore: 0

Vulnerability Summary

Multiple WSO2 products have been identified as vulnerable due to an XML External Entity (XXE) attack abuses a widely available but rarely used feature of XML parsers to access sensitive information.

Vulnerable Product Search on Vulmon Subscribe to Product

wso2 api manager

wso2 api manager analytics 2.2.0

wso2 api manager analytics 2.5.0

wso2 api microgateway 2.2.0

wso2 enterprise integrator

wso2 identity server as key manager 5.7.0

wso2 identity server as key manager 5.6.0

wso2 identity server as key manager 5.9.0

wso2 identity server as key manager 5.0.0

wso2 identity server 5.5.0

wso2 identity server 5.6.0

wso2 identity server 5.4.0

wso2 identity server 5.4.1

wso2 micro integrator 1.0.0