Vulnerability Details CVE-2020-24590
The Management Console in WSO2 API Manager through 3.1.0 and API Microgateway 2.2.0 allows XML Entity Expansion attacks.
Exploit prediction scoring system (EPSS) score
EPSS Score 0.006
EPSS Ranking 67.4%
CVSS Severity
CVSS v3 Score 9.1
CVSS v2 Score 6.4
Products affected by CVE-2020-24590
-
cpe:2.3:a:wso2:api_manager:-
-
cpe:2.3:a:wso2:api_manager:1.0.0
-
cpe:2.3:a:wso2:api_manager:1.1.1
-
cpe:2.3:a:wso2:api_manager:1.10.0
-
cpe:2.3:a:wso2:api_manager:1.2.0
-
cpe:2.3:a:wso2:api_manager:1.3.0
-
cpe:2.3:a:wso2:api_manager:1.3.1
-
cpe:2.3:a:wso2:api_manager:1.4.0
-
cpe:2.3:a:wso2:api_manager:1.5.0
-
cpe:2.3:a:wso2:api_manager:1.6.0
-
cpe:2.3:a:wso2:api_manager:1.7.0
-
cpe:2.3:a:wso2:api_manager:1.8.0
-
cpe:2.3:a:wso2:api_manager:1.9.0
-
cpe:2.3:a:wso2:api_manager:1.9.1
-
cpe:2.3:a:wso2:api_manager:2.0.0
-
cpe:2.3:a:wso2:api_manager:2.1.0
-
cpe:2.3:a:wso2:api_manager:2.2.0
-
cpe:2.3:a:wso2:api_manager:2.5.0
-
cpe:2.3:a:wso2:api_manager:2.6.0
-
cpe:2.3:a:wso2:api_manager:3.0.0
-
cpe:2.3:a:wso2:api_manager:3.1.0
-
cpe:2.3:a:wso2:api_microgateway:2.2.0