Description
Due to the improper configuration of XML parser, user-supplied XML is parsed without applying sufficient restrictions, enabling XML External Entity (XXE) resolution in multiple WSO2 Products. A successful XXE attack could allow a remote, unauthenticated attacker to: * Read sensitive files from the server’s filesystem. * Perform denial-of-service (DoS) attacks, which can render the affected service unavailable.
Problem types
CWE-611 Improper Restriction of XML External Entity Reference
Product status
Any version before 2.0.0
2.1.0 (custom)
2.2.0 (custom)
2.5.0 (custom)
2.6.0 (custom)
3.0.0 (custom)
3.1.0 (custom)
4.0.0 (custom) before 4.0.0.311
4.1.0 (custom) before 4.1.0.152
4.2.0 (custom) before 4.2.0.122
Any version before 6.0.0
6.0.0 (custom)
6.1.0 (custom)
6.1.1 (custom)
6.2.0 (custom)
6.3.0 (custom)
6.4.0 (custom)
6.5.0 (custom)
6.6.0 (custom)
Any version before 4.9.0
4.9.0 (custom)
5.0.0 (custom)
Any version before 1.0.0
1.0.0 (custom)
1.1.0 (custom)
1.2.0 (custom) before 1.2.0.162
4.0.0 (custom) before 4.0.0.132
4.1.0 (custom) before 4.1.0.115
4.2.0 (custom) before 4.2.0.112
Any version before 1.5.0
1.5.0 (custom)
Credits
crnkovic
References
security.docs.wso2.com/...ty-advisories/2025/WSO2-2025-3993/