Impact
The vulnerability resides in the SchemaValidator Mediator’s XML and schema validation routines, which unintentionally permit the resolution of external entities when processing user-supplied XML during validation flows. This flaw allows an attacker with sufficient privileges to read files accessible to the server hosting the affected product, to cause outbound requests to unintended internal or external destinations, and to consume excessive resources through crafted XML that induces parsing overload, potentially leading to denial of service.
Affected Systems
The flaw affects multiple WSO2 products, including WSO2 API Control Plane, WSO2 API Manager, WSO2 Carbon API Gateway, WSO2 Carbon API Management Implementation, WSO2 Traffic Manager, and WSO2 Universal Gateway. No specific version numbers are disclosed in the data, so all versions deployed in production environments should be considered potentially vulnerable.
Risk and Exploitability
The CVSS score of 8.7 marks this as high severity. The EPSS score is not available, and the flaw is not listed in CISA’s KEV catalog. The likely attack vector is remote via crafted XML payloads submitted to mediator endpoints that perform schema validation. If an attacker can reach these endpoints and has sufficient privileges, file read, unintended outbound request, and denial of service outcomes are within reach. The impact is pronounced because it can affect confidentiality, integrity, and availability on the host system.
OpenCVE Enrichment