Vulnerability Monitor

The vendors, products, and vulnerabilities you care about

CVE-2025-2905


Due to the improper configuration of XML parser, user-supplied XML is parsed without applying sufficient restrictions, enabling XML External Entity (XXE) resolution in multiple WSO2 Products. A successful XXE attack could allow a remote, unauthenticated attacker to: * Read sensitive files from the server’s filesystem. * Perform denial-of-service (DoS) attacks, which can render the affected service unavailable.


Published

2025-05-05T09:15:15.923

Last Modified

2025-10-16T12:15:47.167

Status

Modified

Source

ed10eef1-636d-4fbe-9993-6890dfa878f8

Severity

CVSSv3.1: 9.1 (CRITICAL)

Weaknesses
  • Type: Secondary
    CWE-611

Affected Vendors & Products
Type Vendor Product Version/Range Vulnerable?
Application wso2 api_manager ≤ 2.0.0 Yes

References