CVE-2020-13883: WSO2 API Manager

Medium severity, CVSS 6.7. EPSS: 0.8% chance of exploitation in the next 30 days.

In WSO2 API Manager 3.0.0 and earlier, WSO2 API Microgateway 2.2.0, and WSO2 IS as Key Manager 5.9.0 and earlier, Management Console allows XXE during addition or update of a Lifecycle.

Affected products

  • WSO2 API Manager: up to and including 3.0.0
  • WSO2 API Microgateway: version 2.2.0 only
  • WSO2 Identity Server As Key Manager: up to and including 5.9.0

Published 2020-06-06. Last modified 2026-06-17.