PT-2019-18130 · Wso2 · Wso2 Api Manager

Published

2019-05-14

·

Updated

2019-05-14

·

CVE-2019-6512

CVSS v3.1

4.1

Medium

VectorAV:N/AC:L/PR:H/UI:N/S:C/C:L/I:N/A:N
Name of the Vulnerable Software and Affected Versions WSO2 API Manager version 2.6.0
Description An issue in WSO2 API Manager allows forcing the application to perform requests to the internal workstation, enabling SSRF port-scanning, or to adjacent workstations for SSRF network scanning. It also allows file enumeration due to the existence of the file:// wrapper.
Recommendations For WSO2 API Manager version 2.6.0, consider restricting access to the file:// wrapper as a temporary workaround until a patch is available. Additionally, restrict the application's ability to perform requests to internal or adjacent workstations to minimize the risk of SSRF exploitation.

Fix

SSRF

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2019-6512

Affected Products

Wso2 Api Manager