← Zuruck zu CVEs
CVE-2025-9804
CRITICAL9.6
Beschreibung
An improper access control vulnerability exists in multiple WSO2 products due to insufficient permission enforcement in certain internal SOAP Admin Services and System REST APIs. A low-privileged user may exploit this flaw to perform unauthorized operations, including accessing server-level information. This vulnerability affects only internal administrative interfaces. APIs exposed through the WSO2 API Manager's API Gateway remain unaffected.
CVE Details
CVSS v3.1 Bewertung9.6
SchweregradCRITICAL
CVSS VektorCVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H
AngriffsvektorADJACENT_NETWORK
KomplexitatLOW
Erforderliche PrivilegienNONE
BenutzerinteraktionNONE
Veroffentlicht10/16/2025
Zuletzt geandert11/21/2025
Quellenvd
Honeypot-Sichtungen0
Betroffene Produkte
wso2:api_control_planewso2:api_managerwso2:api_manager_analyticswso2:data_analytics_serverwso2:enterprise_integratorwso2:enterprise_mobility_managerwso2:enterprise_service_buswso2:identity_serverwso2:identity_server_analyticswso2:identity_server_as_key_managerwso2:open_banking_amwso2:open_banking_iamwso2:open_banking_kmwso2:traffic_managerwso2:universal_gateway
Schwachen (CWE)
CWE-284
Referenzen
https://security.docs.wso2.com/en/latest/security-announcements/security-advisories/2025/WSO2-2025-4503/(ed10eef1-636d-4fbe-9993-6890dfa878f8)
IOC Korrelationen
Keine Korrelationen erfasst
This product uses data from the NVD API but is not endorsed or certified by the NVD.