PT-2019-18130 · Wso2 · Wso2 Api Manager
Published
2019-05-14
·
Updated
2019-05-14
·
CVE-2019-6512
CVSS v3.1
4.1
Medium
| Vector | AV:N/AC:L/PR:H/UI:N/S:C/C:L/I:N/A:N |
Name of the Vulnerable Software and Affected Versions
WSO2 API Manager version 2.6.0
Description
An issue in WSO2 API Manager allows forcing the application to perform requests to the internal workstation, enabling SSRF port-scanning, or to adjacent workstations for SSRF network scanning. It also allows file enumeration due to the existence of the
file:// wrapper.Recommendations
For WSO2 API Manager version 2.6.0, consider restricting access to the
file:// wrapper as a temporary workaround until a patch is available. Additionally, restrict the application's ability to perform requests to internal or adjacent workstations to minimize the risk of SSRF exploitation.Fix
SSRF
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Wso2 Api Manager