PT-2025-19376 · Wso2 · Wso2 Api Manager
Crnkovic
·
Published
2025-05-05
·
Updated
2025-11-10
·
CVE-2025-2905
CVSS v2.0
9.4
Critical
| Vector | AV:N/AC:L/Au:N/C:C/I:N/A:C |
Name of the Vulnerable Software and Affected Versions
WSO2 API Manager versions 2.0.0 and earlier
Description
An XML External Entity (XXE) vulnerability exists in the gateway component of WSO2 API Manager due to insufficient validation of XML input in crafted URL paths. User-supplied XML is parsed without appropriate restrictions, enabling external entity resolution. A remote, unauthenticated attacker can exploit this to read files from the server’s filesystem or perform denial-of-service (DoS) attacks. On systems running JDK 7 or early JDK 8, the full content of files may be exposed. On later versions of JDK 8 and newer, only the first line of a file may be read due to improvements in XML parser behavior. DoS attacks, such as "Billion Laughs" payloads, can cause service disruption.
Recommendations
Apply the patch WSO2-2016-0151 to versions 2.0.0 and earlier.
Fix
DoS
XXE
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Wso2 Api Manager