CVE-2023-6836

Multiple WSO2 products have been identified as vulnerable due to an XML External Entity (XXE) attack abuses a widely available but rarely used feature of XML parsers to access sensitive information.
Configurations

Configuration 1 (hide)

cpe:2.3:a:wso2:api_manager:*:*:*:*:*:*:*:*

Configuration 2 (hide)

OR cpe:2.3:a:wso2:api_manager_analytics:2.2.0:*:*:*:*:*:*:*
cpe:2.3:a:wso2:api_manager_analytics:2.5.0:*:*:*:*:*:*:*

Configuration 3 (hide)

cpe:2.3:a:wso2:api_microgateway:2.2.0:*:*:*:*:*:*:*

Configuration 4 (hide)

cpe:2.3:a:wso2:enterprise_integrator:*:*:*:*:*:*:*:*

Configuration 5 (hide)

OR cpe:2.3:a:wso2:identity_server_as_key_manager:5.0.0:*:*:*:*:*:*:*
cpe:2.3:a:wso2:identity_server_as_key_manager:5.6.0:*:*:*:*:*:*:*
cpe:2.3:a:wso2:identity_server_as_key_manager:5.7.0:*:*:*:*:*:*:*
cpe:2.3:a:wso2:identity_server_as_key_manager:5.9.0:*:*:*:*:*:*:*

Configuration 6 (hide)

OR cpe:2.3:a:wso2:identity_server:5.4.0:*:*:*:*:*:*:*
cpe:2.3:a:wso2:identity_server:5.4.1:*:*:*:*:*:*:*
cpe:2.3:a:wso2:identity_server:5.5.0:*:*:*:*:*:*:*
cpe:2.3:a:wso2:identity_server:5.6.0:*:*:*:*:*:*:*

Configuration 7 (hide)

cpe:2.3:a:wso2:micro_integrator:1.0.0:*:*:*:*:*:*:*

History

19 Dec 2023, 13:52

Type Values Removed Values Added
CPE cpe:2.3:a:wso2:enterprise_integrator:*:*:*:*:*:*:*:*
cpe:2.3:a:wso2:api_manager_analytics:2.2.0:*:*:*:*:*:*:*
cpe:2.3:a:wso2:api_manager_analytics:2.5.0:*:*:*:*:*:*:*
cpe:2.3:a:wso2:api_manager:*:*:*:*:*:*:*:*
cpe:2.3:a:wso2:identity_server_as_key_manager:5.7.0:*:*:*:*:*:*:*
cpe:2.3:a:wso2:identity_server_as_key_manager:5.0.0:*:*:*:*:*:*:*
cpe:2.3:a:wso2:identity_server_as_key_manager:5.9.0:*:*:*:*:*:*:*
cpe:2.3:a:wso2:identity_server:5.4.0:*:*:*:*:*:*:*
cpe:2.3:a:wso2:identity_server:5.5.0:*:*:*:*:*:*:*
cpe:2.3:a:wso2:identity_server:5.4.1:*:*:*:*:*:*:*
cpe:2.3:a:wso2:api_microgateway:2.2.0:*:*:*:*:*:*:*
cpe:2.3:a:wso2:identity_server_as_key_manager:5.6.0:*:*:*:*:*:*:*
cpe:2.3:a:wso2:identity_server:5.6.0:*:*:*:*:*:*:*
cpe:2.3:a:wso2:micro_integrator:1.0.0:*:*:*:*:*:*:*
References () https://security.docs.wso2.com/en/latest/security-announcements/security-advisories/2021/WSO2-2020-0716/ - () https://security.docs.wso2.com/en/latest/security-announcements/security-advisories/2021/WSO2-2020-0716/ - Vendor Advisory
First Time Wso2 enterprise Integrator
Wso2 api Manager
Wso2 identity Server
Wso2
Wso2 api Manager Analytics
Wso2 micro Integrator
Wso2 api Microgateway
Wso2 identity Server As Key Manager
CVSS v2 : unknown
v3 : 4.6
v2 : unknown
v3 : 7.5

15 Dec 2023, 13:41

Type Values Removed Values Added
Summary
  • (es) Se han identificado varios productos WSO2 como vulnerables debido a que un ataque de entidad externa XML (XXE) abusa de una característica ampliamente disponible pero rara vez utilizada de los analizadores XML para acceder a información confidencial.

15 Dec 2023, 10:15

Type Values Removed Values Added
New CVE

Information

Published : 2023-12-15 10:15

Updated : 2023-12-19 13:52


NVD link : CVE-2023-6836

Mitre link : CVE-2023-6836

CVE.ORG link : CVE-2023-6836


JSON object : View

Products Affected

wso2

  • micro_integrator
  • api_microgateway
  • api_manager
  • enterprise_integrator
  • identity_server
  • api_manager_analytics
  • identity_server_as_key_manager
CWE
CWE-611

Improper Restriction of XML External Entity Reference