PT-2019-18130 · Wso2 · Wso2 Api Manager

Publicado

2019-05-14

·

Atualizado

2019-05-14

·

CVE-2019-6512

CVSS v3.1

4.1

Média

VetorAV:N/AC:L/PR:H/UI:N/S:C/C:L/I:N/A:N
Name of the Vulnerable Software and Affected Versions WSO2 API Manager version 2.6.0
Description An issue in WSO2 API Manager allows forcing the application to perform requests to the internal workstation, enabling SSRF port-scanning, or to adjacent workstations for SSRF network scanning. It also allows file enumeration due to the existence of the file:// wrapper.
Recommendations For WSO2 API Manager version 2.6.0, consider restricting access to the file:// wrapper as a temporary workaround until a patch is available. Additionally, restrict the application's ability to perform requests to internal or adjacent workstations to minimize the risk of SSRF exploitation.

Correção

SSRF

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

CVE-2019-6512

Produtos afetados

Wso2 Api Manager