CVE-2020-11885: WSO2 Enterprise Integrator

High severity, CVSS 7.2. EPSS: 0.8% chance of exploitation in the next 30 days.

WSO2 Enterprise Integrator through 6.6.0 has an XXE vulnerability where a user (with admin console access) can use the XML validator to make unintended network invocations such as SSRF via an uploaded file.

Affected products

  • WSO2 Enterprise Integrator: up to and including 6.6.0

Published 2020-04-17. Last modified 2026-06-17.