peter bassill · operator
$ cve CVE-2021-42646 JSON

CVE-2021-42646

9.1
CRITICAL · CVSS 3.1 · EPSS 3.8% (pctl 90)

In your normal cycle

Critical by CVSS (9.1), but no sign of active exploitation.

Description

XML External Entity (XXE) vulnerability in the file based service provider creation feature of the Management Console in WSO2 API Manager 2.6.0, 3.0.0, 3.1.0, 3.2.0, and 4.0.0; and WSO2 IS as Key Manager 5.7.0, 5.9.0, and 5.10.0; and WSO2 Identity Server 5.7.0, 5.8.0, 5.9.0, 5.10.0, and 5.11.0. Allows attackers to gain read access to sensitive information or cause a denial of service via crafted GET requests.

Scoring

CVSS9.1 (CRITICAL, v3.1)
VectorCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:H
EPSS3.76% — more likely to be exploited than 90% of all CVEs
WeaknessCWE-611
On CISA KEVno
Public exploitnone known
Published2022-05-11
Last modified2026-06-17

Affected (3)

VendorProduct
wso2api manager
wso2identity server
wso2identity server as key manager

References

→ the Explorer  ·  watch your stack  ·  NVD