Description
The Management Console in WSO2 API Manager through 3.1.0 and API Microgateway 2.2.0 allows XML Entity Expansion attacks.
Remediation
References
https://docs.wso2.com/display/Security/Security+Advisory+WSO2-2020-0742
Related Vulnerabilities
CVE-2022-34811 Vulnerability in maven package org.jenkins-ci.plugins:xpath-config-viewer
CVE-2022-36898 Vulnerability in maven package com.compuware.jenkins:compuware-ispw-operations
CVE-2019-10419 Vulnerability in maven package org.jenkins-ci.plugins:application-director-plugin
CVE-2014-3603 Vulnerability in maven package org.opensaml:opensaml
CVE-2023-26473 Vulnerability in maven package org.xwiki.platform:xwiki-platform-web-templates