CVE-2023-6836
 
Severity Score
7.5
*CVSS v3.1
Exploit Likelihood
*EPSS
Affected Versions
*CPE
Public Exploits
0
*Multiple Sources
Exploited in Wild
-
*KEV
Decision
-
*SSVC
Descriptions
Multiple WSO2 products have been identified as vulnerable due to an XML External Entity (XXE) attack abuses a widely available but rarely used feature of XML parsers to access sensitive information.
Se han identificado varios productos WSO2 como vulnerables debido a que un ataque de entidad externa XML (XXE) abusa de una característica ampliamente disponible pero rara vez utilizada de los analizadores XML para acceder a información confidencial.
*Credits:
N/A
CVSS Scores
Attack Vector
Attack Complexity
Privileges Required
User Interaction
Scope
Confidentiality
Integrity
Availability
Attack Vector
Attack Complexity
Privileges Required
User Interaction
Scope
Confidentiality
Integrity
Availability
Attack Vector
Attack Complexity
Authentication
Confidentiality
Integrity
Availability
* Common Vulnerability Scoring System
SSVC
- Decision:-
Exploitation
Automatable
Tech. Impact
* Organization's Worst-case Scenario
Timeline
- 2023-12-15 CVE Reserved
- 2023-12-15 CVE Published
- 2024-08-02 CVE Updated
- 2025-03-30 EPSS Updated
- ---------- Exploited in Wild
- ---------- KEV Due Date
- ---------- First Exploit
CWE
- CWE-611: Improper Restriction of XML External Entity Reference
CAPEC
- CAPEC-250: XML Injection
References (1)
URL | Tag | Source |
---|
URL | Date | SRC |
---|
URL | Date | SRC |
---|
Affected Vendors, Products, and Versions
Vendor | Product | Version | Other | Status | ||||||
---|---|---|---|---|---|---|---|---|---|---|
Vendor | Product | Version | Other | Status | <-- --> | Vendor | Product | Version | Other | Status |
Wso2 Search vendor "Wso2" | Api Manager Search vendor "Wso2" for product "Api Manager" | <= 3.0.0 Search vendor "Wso2" for product "Api Manager" and version " <= 3.0.0" | - |
Affected
| ||||||
Wso2 Search vendor "Wso2" | Api Manager Analytics Search vendor "Wso2" for product "Api Manager Analytics" | 2.2.0 Search vendor "Wso2" for product "Api Manager Analytics" and version "2.2.0" | - |
Affected
| ||||||
Wso2 Search vendor "Wso2" | Api Manager Analytics Search vendor "Wso2" for product "Api Manager Analytics" | 2.5.0 Search vendor "Wso2" for product "Api Manager Analytics" and version "2.5.0" | - |
Affected
| ||||||
Wso2 Search vendor "Wso2" | Api Microgateway Search vendor "Wso2" for product "Api Microgateway" | 2.2.0 Search vendor "Wso2" for product "Api Microgateway" and version "2.2.0" | - |
Affected
| ||||||
Wso2 Search vendor "Wso2" | Enterprise Integrator Search vendor "Wso2" for product "Enterprise Integrator" | <= 6.6.0 Search vendor "Wso2" for product "Enterprise Integrator" and version " <= 6.6.0" | - |
Affected
| ||||||
Wso2 Search vendor "Wso2" | Identity Server As Key Manager Search vendor "Wso2" for product "Identity Server As Key Manager" | 5.0.0 Search vendor "Wso2" for product "Identity Server As Key Manager" and version "5.0.0" | - |
Affected
| ||||||
Wso2 Search vendor "Wso2" | Identity Server As Key Manager Search vendor "Wso2" for product "Identity Server As Key Manager" | 5.6.0 Search vendor "Wso2" for product "Identity Server As Key Manager" and version "5.6.0" | - |
Affected
| ||||||
Wso2 Search vendor "Wso2" | Identity Server As Key Manager Search vendor "Wso2" for product "Identity Server As Key Manager" | 5.7.0 Search vendor "Wso2" for product "Identity Server As Key Manager" and version "5.7.0" | - |
Affected
| ||||||
Wso2 Search vendor "Wso2" | Identity Server As Key Manager Search vendor "Wso2" for product "Identity Server As Key Manager" | 5.9.0 Search vendor "Wso2" for product "Identity Server As Key Manager" and version "5.9.0" | - |
Affected
| ||||||
Wso2 Search vendor "Wso2" | Identity Server Search vendor "Wso2" for product "Identity Server" | 5.4.0 Search vendor "Wso2" for product "Identity Server" and version "5.4.0" | - |
Affected
| ||||||
Wso2 Search vendor "Wso2" | Identity Server Search vendor "Wso2" for product "Identity Server" | 5.4.1 Search vendor "Wso2" for product "Identity Server" and version "5.4.1" | - |
Affected
| ||||||
Wso2 Search vendor "Wso2" | Identity Server Search vendor "Wso2" for product "Identity Server" | 5.5.0 Search vendor "Wso2" for product "Identity Server" and version "5.5.0" | - |
Affected
| ||||||
Wso2 Search vendor "Wso2" | Identity Server Search vendor "Wso2" for product "Identity Server" | 5.6.0 Search vendor "Wso2" for product "Identity Server" and version "5.6.0" | - |
Affected
| ||||||
Wso2 Search vendor "Wso2" | Micro Integrator Search vendor "Wso2" for product "Micro Integrator" | 1.0.0 Search vendor "Wso2" for product "Micro Integrator" and version "1.0.0" | - |
Affected
|