← Back

CVE-2020-12719

nvd nist
Published: May 8, 2020Modified: Jun 17, 2026

JSON object

Loading...
7.2
Vector
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H
Exploitability: 1.2 / Impact: 5.9
Source: NVD

Description

XXE during an EventPublisher update can occur in Management Console in WSO2 API Manager 3.0.0 and earlier, API Manager Analytics 2.5.0 and earlier, API Microgateway 2.2.0, Enterprise Integrator 6.4.0 and earlier, IS as Key Manager 5.9.0 and earlier, Identity Server 5.9.0 and earlier, and Identity Server Analytics 5.6.0 and earlier.

Affected (7)

7 products
Api Manager
Api Manager Analytics
Api Microgateway
Enterprise Integrator
Identity Server
Identity Server Analytics
Identity Server As Key Manager
Configuration A
7 vulnerable
Vulnerable SoftwareAffected Versions
Up to 3.0.0
Up to 2.5.0
Version 2.2.0
Up to 6.4.0
Up to 5.9.0
Up to 5.6.0
Up to 5.9.0

References (2)

Source: af854a3a-2127-422b-91ae-364da2661108
Vendor Advisory

Timeline

No history available yet.