The Management Console in certain WSO2 products allows XXE attacks during EventReceiver updates. This affects API Manager through 3.0.0, API Manager Analytics 2.2.0 and 2.5.0, API Microgateway 2.2.0, Enterprise Integrator 6.2.0 and 6.3.0, and Identity Server Analytics through 5.6.0.
Metrics
Affected Vendors & Products
References
History
No history.

Status: PUBLISHED
Assigner: mitre
Published:
Updated: 2024-08-04T15:19:08.739Z
Reserved: 2020-08-21T00:00:00
Link: CVE-2020-24591

No data.

Status : Modified
Published: 2020-08-21T20:15:11.093
Modified: 2024-11-21T05:15:06.473
Link: CVE-2020-24591

No data.