9.1

CVE-2021-42646

XML External Entity (XXE) vulnerability in the file based service provider creation feature of the Management Console in WSO2 API Manager 2.6.0, 3.0.0, 3.1.0, 3.2.0, and 4.0.0; and WSO2 IS as Key Manager 5.7.0, 5.9.0, and 5.10.0; and WSO2 Identity Server 5.7.0, 5.8.0, 5.9.0, 5.10.0, and 5.11.0. Allows attackers to gain read access to sensitive information or cause a denial of service via crafted GET requests.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Wso2Api Manager Version2.6.0
Wso2Api Manager Version3.0.0
Wso2Api Manager Version3.1.0
Wso2Api Manager Version3.2.0
Wso2Api Manager Version4.0.0
Wso2Identity Server Version5.7.0
Wso2Identity Server Version5.8.0
Wso2Identity Server Version5.9.0
Wso2Identity Server Version5.10.0
Wso2Identity Server Version5.11.0
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 3.67% 0.882
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
nvd@nist.gov 9.1 3.9 5.2
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:H
nvd@nist.gov 6.4 10 4.9
AV:N/AC:L/Au:N/C:P/I:N/A:P
CWE-611 Improper Restriction of XML External Entity Reference

The product processes an XML document that can contain XML entities with URIs that resolve to documents outside of the intended sphere of control, causing the product to embed incorrect documents into its output.

http://packetstormsecurity.com/files/167465/WSO2-Management-Console-XML-Injection.html
Third Party Advisory
VDB Entry
http://seclists.org/fulldisclosure/2022/Jun/7
Third Party Advisory
Mailing List
https://github.com/wso2/carbon-identity-framework/pull/3472
Patch
Third Party Advisory
https://security.docs.wso2.com/en/latest/security-announcements/security-advisories/2021/WSO2-2021-1289/