CVE-2021-42646
9.1
CRITICAL · CVSS 3.1 · EPSS 3.8% (pctl 90)
In your normal cycle
Critical by CVSS (9.1), but no sign of active exploitation.
Description
XML External Entity (XXE) vulnerability in the file based service provider creation feature of the Management Console in WSO2 API Manager 2.6.0, 3.0.0, 3.1.0, 3.2.0, and 4.0.0; and WSO2 IS as Key Manager 5.7.0, 5.9.0, and 5.10.0; and WSO2 Identity Server 5.7.0, 5.8.0, 5.9.0, 5.10.0, and 5.11.0. Allows attackers to gain read access to sensitive information or cause a denial of service via crafted GET requests.
Scoring
| CVSS | 9.1 (CRITICAL, v3.1) |
|---|---|
| Vector | CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:H |
| EPSS | 3.76% — more likely to be exploited than 90% of all CVEs |
| Weakness | CWE-611 |
| On CISA KEV | no |
| Public exploit | none known |
| Published | 2022-05-11 |
| Last modified | 2026-06-17 |
Affected (3)
| Vendor | Product |
|---|---|
| wso2 | api manager |
| wso2 | identity server |
| wso2 | identity server as key manager |
References
- http://packetstormsecurity.com/files/167465/WSO2-Management-Console-XML-Injection.html
- http://seclists.org/fulldisclosure/2022/Jun/7
- https://github.com/wso2/carbon-identity-framework/pull/3472
- https://security.docs.wso2.com/en/latest/security-announcements/security-advisories/2021/WSO2-2021-1289/
- http://packetstormsecurity.com/files/167465/WSO2-Management-Console-XML-Injection.html
- http://seclists.org/fulldisclosure/2022/Jun/7
- https://github.com/wso2/carbon-identity-framework/pull/3472
- https://security.docs.wso2.com/en/latest/security-announcements/security-advisories/2021/WSO2-2021-1289/
→ the Explorer · watch your stack · NVD