Description
In WSO2 API Manager 3.0.0 and earlier, WSO2 API Microgateway 2.2.0, and WSO2 IS as Key Manager 5.9.0 and earlier, Management Console allows XXE during addition or update of a Lifecycle.
Remediation
References
https://docs.wso2.com/display/Security/Security+Advisory+WSO2-2020-0727
Related Vulnerabilities
CVE-2012-5633 Vulnerability in maven package org.apache.cxf:cxf-rt-core
CVE-2023-35152 Vulnerability in maven package org.xwiki.platform:xwiki-platform-like-ui
CVE-2023-25572 Vulnerability in maven package org.webjars.npm:react-admin
CVE-2018-6341 Vulnerability in maven package org.webjars.bowergithub.vuejs:vue
CVE-2019-1003031 Vulnerability in maven package org.jenkins-ci.plugins:matrix-project