CVE-2025-10713

CRITICAL WAF: High
CVSS 9.1 Published: 2025-11-05
CWE-611

An XML External Entity (XXE) vulnerability exists in multiple WSO2 products due to improper configuration of the XML parser. The application parses user-supplied XML without applying sufficient restrictions, allowing resolution of external entities. A successful attack could enable a remote, unauthenticated attacker to read sensitive files from the server's filesystem or perform denial-of-service (DoS) attacks that render affected services unavailable.

WAF Coverage Analysis

XML External Entity (XXE) High WAF Coverage

OWASP: A05:2021 Security Misconfiguration

941xxx - XSS / XXE

Affected Software

VendorProductVersion
wso2api_control_plane4.5.0
wso2api_manager3.1.0
wso2api_manager3.2.0
wso2api_manager3.2.1
wso2api_manager4.0.0
wso2api_manager4.1.0
wso2api_manager4.2.0
wso2api_manager4.3.0
wso2api_manager4.4.0
wso2api_manager4.5.0

References

Back to CVE Database