CVE-2025-10713: XML External Entity (XXE) Vulnerability in Multiple WSO2 Products Due to Improper XML Parser Configuration
An XML External Entity (XXE) vulnerability exists in multiple WSO2 products due to improper configuration of the XML parser. The application parses user-supplied XML without applying sufficient restrictions, allowing resolution of external entities.
A successful attack could enable a remote, unauthenticated attacker to read sensitive files from the server's filesystem or perform denial-of-service (DoS) attacks that render affected services unavailable.
Affected Software
Remediation
Information
Event History
Frequently Asked Questions
What is the severity of CVE-2025-10713?
CVE-2025-10713 is classified as a critical vulnerability due to the potential for remote code execution from XML External Entity (XXE) attacks.
How do I fix CVE-2025-10713?
To fix CVE-2025-10713, you should reconfigure the XML parser to disable the resolution of external entities and update your WSO2 products to the latest version.
Which WSO2 products are affected by CVE-2025-10713?
CVE-2025-10713 affects multiple WSO2 products that utilize XML parsers without proper configuration.
What are the potential impacts of CVE-2025-10713?
The potential impacts of CVE-2025-10713 include unauthorized access to internal systems, data exfiltration, and possible system compromise.
How can I detect if CVE-2025-10713 is present in my WSO2 environment?
You can detect CVE-2025-10713 in your WSO2 environment by reviewing your XML parser configurations and checking your software versions for updates.