CVE-2020-24591: XEE
The Management Console in certain WSO2 products allows XXE attacks during EventReceiver updates. This affects API Manager through 3.0.0, API Manager Analytics 2.2.0 and 2.5.0, API Microgateway 2.2.0, Enterprise Integrator 6.2.0 and 6.3.0, and Identity Server Analytics through 5.6.0.
Affected Software
Event History
Frequently Asked Questions
What is CVE-2020-24591?
CVE-2020-24591 is a vulnerability in certain WSO2 products that allows XXE attacks during EventReceiver updates.
Which WSO2 products are affected by CVE-2020-24591?
CVE-2020-24591 affects API Manager through version 3.0.0, API Manager Analytics versions 2.2.0 and 2.5.0, API Microgateway version 2.2.0, Enterprise Integrator versions 6.2.0 and 6.3.0, and Identity Server Analytics through version 5.6.0.
What is the severity of CVE-2020-24591?
The severity of CVE-2020-24591 is medium with a score of 6.5.
How can XXE attacks be performed during EventReceiver updates in WSO2 products?
XXE attacks can be performed during EventReceiver updates in WSO2 products through the Management Console.
How can I fix the CVE-2020-24591 vulnerability in WSO2 products?
To fix the CVE-2020-24591 vulnerability, it is recommended to upgrade the affected WSO2 products to the latest patched versions.