CVE-2025-2905 | Teknoloji dünyasından en güncel haberleri ve güvenlikle ilgili gelişmeleri takip edin.

Due to the improper configuration of XML parser, user-supplied XML is parsed without applying sufficient restrictions, enabling XML External Entity (XXE) resolu…
Critical CVSS: 9.1

CVE-2025-2905

Due to the improper configuration of XML parser, user-supplied XML is parsed without applying sufficient restrictions, enabling XML External Entity (XXE) resolution in multiple WSO2 Products.

A successful XXE attack could allow a remote, unauthenticated attacker to:
* Read sensitive files from the server’s filesystem.
* Perform denial-of-service (DoS) attacks, which can render the affected service unavailable.
Vendor
Wso2
Product
Api Manager
CWE
CWE-611
Yayın Tarihi
2025-05-05 09:15:15
Güncelleme
2025-10-16 12:15:47
Source Identifier
ed10eef1-636d-4fbe-9993-6890dfa878f8
KEV Date Added
-

Kategoriler

Referanslar