First published: Fri Apr 17 2020(Updated: )
WSO2 Enterprise Integrator through 6.6.0 has an XXE vulnerability where a user (with admin console access) can use the XML validator to make unintended network invocations such as SSRF via an uploaded file.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
WSO2 Enterprise Integrator | <=6.6.0 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2020-11885 is a vulnerability in WSO2 Enterprise Integrator through version 6.6.0 that allows a user with admin console access to make unintended network invocations via an uploaded file.
CVE-2020-11885 has a severity keyword of 'high' and a severity value of 7.2.
CVE-2020-11885 affects WSO2 Enterprise Integrator versions up to and including 6.6.0.
An XXE vulnerability is a type of vulnerability that allows attackers to read files, execute network requests, and perform denial-of-service attacks by exploiting XML parsing vulnerabilities.
To fix CVE-2020-11885, it is recommended to upgrade WSO2 Enterprise Integrator to a version that is not affected by this vulnerability.