Medium severity6.5NVD Advisory· Published Aug 21, 2020· Updated Jun 17, 2026
CVE-2020-24591
CVE-2020-24591
Description
The Management Console in certain WSO2 products allows XXE attacks during EventReceiver updates. This affects API Manager through 3.0.0, API Manager Analytics 2.2.0 and 2.5.0, API Microgateway 2.2.0, Enterprise Integrator 6.2.0 and 6.3.0, and Identity Server Analytics through 5.6.0.
Affected products
1- WSO2/API Managerdescription
Patches
Vulnerability mechanics
References
1- docs.wso2.com/display/Security/Security+Advisory+WSO2-2020-0728nvdVendor Advisory
News mentions
0No linked articles in our index yet.