CVE-2020-11885: XEE
WSO2 Enterprise Integrator through 6.6.0 has an XXE vulnerability where a user (with admin console access) can use the XML validator to make unintended network invocations such as SSRF via an uploaded file.
Affected Software
Event History
Frequently Asked Questions
What is CVE-2020-11885?
CVE-2020-11885 is a vulnerability in WSO2 Enterprise Integrator through version 6.6.0 that allows a user with admin console access to make unintended network invocations via an uploaded file.
How severe is CVE-2020-11885?
CVE-2020-11885 has a severity keyword of 'high' and a severity value of 7.2.
How does CVE-2020-11885 affect WSO2 Enterprise Integrator?
CVE-2020-11885 affects WSO2 Enterprise Integrator versions up to and including 6.6.0.
What is an XXE vulnerability?
An XXE vulnerability is a type of vulnerability that allows attackers to read files, execute network requests, and perform denial-of-service attacks by exploiting XML parsing vulnerabilities.
How can I fix CVE-2020-11885?
To fix CVE-2020-11885, it is recommended to upgrade WSO2 Enterprise Integrator to a version that is not affected by this vulnerability.