Description
The Management Console in WSO2 API Manager through 3.1.0 and API Microgateway 2.2.0 allows XML Entity Expansion attacks.
Remediation
References
https://docs.wso2.com/display/Security/Security+Advisory+WSO2-2020-0742
Related Vulnerabilities
CVE-2022-34806 Vulnerability in maven package org.jenkins-ci.plugins:jigomerge
CVE-2018-1000865 Vulnerability in maven package org.kohsuke:groovy-sandbox
CVE-2020-2240 Vulnerability in maven package org.jenkins-ci.plugins:database
CVE-2023-22849 Vulnerability in maven package org.apache.sling:org.apache.sling.cms.ui
CVE-2013-4152 Vulnerability in maven package org.springframework:spring-oxm