CVE-2019-6512: WSO2 API Manager

Medium severity, CVSS 4.1. EPSS: 1.1% chance of exploitation in the next 30 days.

An issue was discovered in WSO2 API Manager 2.6.0. It is possible to force the application to perform requests to the internal workstation (SSRF port-scanning), other adjacent workstations (SSRF network scanning), or to enumerate files because of the existence of the file:// wrapper.

Affected products

  • WSO2 API Manager: version 2.6.0 only

Published 2019-05-14. Last modified 2026-06-17.