Vulnerabilities > CVE-2019-6512 - Server-Side Request Forgery (SSRF) vulnerability in Wso2 API Manager 2.6.0
Attack vector
NETWORK Attack complexity
LOW Privileges required
HIGH Confidentiality impact
LOW Integrity impact
NONE Availability impact
NONE Summary
An issue was discovered in WSO2 API Manager 2.6.0. It is possible to force the application to perform requests to the internal workstation (SSRF port-scanning), other adjacent workstations (SSRF network scanning), or to enumerate files because of the existence of the file:// wrapper.
Vulnerable Configurations
Part | Description | Count |
---|---|---|
Application | 1 |