Due to the improper configuration of XML parser, user-supplied XML is parsed without applying sufficient restrictions, enabling XML External Entity (XXE) resolution in multiple WSO2 Products.
A successful XXE attack could allow a remote, unauthenticated attacker to:
| Software | From | Fixed in |
|---|---|---|
org.wso2.am / am-distribution-parent
|
- | 2.1.0 |
| wso2 / api_manager | - | 2.0.0.x |