CVE-2019-6512 Information
Feb 14, 2021
cve
Description
An issue was discovered in WSO2 API Manager 2.6.0. It is possible to force the application to perform requests to the internal workstation (SSRF port-scanning) other adjacent workstations (SSRF network scanning) or to enumerate files because of the existence of the file:// wrapper.
CVSS Vector
CVSS:3.0/AV:N/AC:L/PR:H/UI:N/S:C/C:L/I:N/A:N
Reference
https://wso2.com/security-patch-releases/api-manager https://www.excellium-services.com/cert-xlm-advisory
Attack Complexity
LOW
Privileges Required
HIGH
User Interaction Required
HIGH
Scope
NONE
Confidentiality Impact
CHANGED
Integrity Impact
LOW
Availability Impact
NONE
Base Score
NONE
Base Severity
4.1
Share on: