An issue was discovered in WSO2 API Manager 2.6.0. It is possible to force the application to perform requests to the internal workstation (SSRF port-scanning), other adjacent workstations (SSRF network scanning), or to enumerate files because of the existence of the file:// wrapper.
History

No history.

cve-icon MITRE

Status: PUBLISHED

Assigner: mitre

Published: 2019-05-14T14:24:33

Updated: 2024-08-04T20:23:22.050Z

Reserved: 2019-01-22T00:00:00

Link: CVE-2019-6512

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Analyzed

Published: 2019-05-14T15:29:00.383

Modified: 2019-05-14T17:36:23.497

Link: CVE-2019-6512

cve-icon Redhat

No data.