PT-2025-19376 · Wso2 · Wso2 Api Manager

Crnkovic

·

Published

2025-05-05

·

Updated

2025-11-10

·

CVE-2025-2905

CVSS v2.0

9.4

Critical

VectorAV:N/AC:L/Au:N/C:C/I:N/A:C
Name of the Vulnerable Software and Affected Versions WSO2 API Manager versions 2.0.0 and earlier
Description An XML External Entity (XXE) vulnerability exists in the gateway component of WSO2 API Manager due to insufficient validation of XML input in crafted URL paths. User-supplied XML is parsed without appropriate restrictions, enabling external entity resolution. A remote, unauthenticated attacker can exploit this to read files from the server’s filesystem or perform denial-of-service (DoS) attacks. On systems running JDK 7 or early JDK 8, the full content of files may be exposed. On later versions of JDK 8 and newer, only the first line of a file may be read due to improvements in XML parser behavior. DoS attacks, such as "Billion Laughs" payloads, can cause service disruption.
Recommendations Apply the patch WSO2-2016-0151 to versions 2.0.0 and earlier.

Fix

DoS

XXE

Weakness Enumeration

Related Identifiers

BDU:2026-02584
CVE-2025-2905
GHSA-H94W-8QHG-3XMC

Affected Products

Wso2 Api Manager