Does this Woodstox vulnerability affect the API Gateway?
All supported gateway versions
The Gateway is unlikely to be impacted by this CVE, as the Woodstox library is a transitive dependency of Apache CXF. Furthermore, the Gateway's usage of CXF is limited to the process controller API, and the vulnerable functionality within Woodstox is not utilized in this context.