CVE-2020-24591: WSO2 API Manager

Medium severity, CVSS 6.5. EPSS: 1% chance of exploitation in the next 30 days.

The Management Console in certain WSO2 products allows XXE attacks during EventReceiver updates. This affects API Manager through 3.0.0, API Manager Analytics 2.2.0 and 2.5.0, API Microgateway 2.2.0, Enterprise Integrator 6.2.0 and 6.3.0, and Identity Server Analytics through 5.6.0.

Affected products

  • WSO2 API Manager: up to and including 3.0.0
  • WSO2 API Manager Analytics: version 2.2.0 only; version 2.5.0 only
  • WSO2 API Microgateway: version 2.2.0 only
  • WSO2 Enterprise Integrator: version 6.2.0 only; version 6.3.0 only
  • WSO2 Identity Server Analytics: up to and including 5.6.0

Published 2020-08-21. Last modified 2026-06-17.