CVE-2021-42646

CRITICAL

WSO2 API Manager/IS/Identity Server XML External Entity Injection

Title source: llm
STIX 2.1

Description

XML External Entity (XXE) vulnerability in the file based service provider creation feature of the Management Console in WSO2 API Manager 2.6.0, 3.0.0, 3.1.0, 3.2.0, and 4.0.0; and WSO2 IS as Key Manager 5.7.0, 5.9.0, and 5.10.0; and WSO2 Identity Server 5.7.0, 5.8.0, 5.9.0, 5.10.0, and 5.11.0. Allows attackers to gain read access to sensitive information or cause a denial of service via crafted GET requests.

Scores

CVSS v3 9.1
EPSS 0.0367
EPSS Percentile 88.2%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:H

Details

CWE
CWE-611
Status published
Products (13)
wso2/api_manager 2.6.0
wso2/api_manager 3.0.0
wso2/api_manager 3.1.0
wso2/api_manager 3.2.0
wso2/api_manager 4.0.0
wso2/identity_server 5.7.0
wso2/identity_server 5.8.0
wso2/identity_server 5.9.0
wso2/identity_server 5.10.0
wso2/identity_server 5.11.0
... and 3 more
Published May 11, 2022
Tracked Since Feb 18, 2026