TROYANOSYVIRUS
Back to CVEs

CVE-2025-9804

CRITICAL
9.6

Description

An improper access control vulnerability exists in multiple WSO2 products due to insufficient permission enforcement in certain internal SOAP Admin Services and System REST APIs. A low-privileged user may exploit this flaw to perform unauthorized operations, including accessing server-level information. This vulnerability affects only internal administrative interfaces. APIs exposed through the WSO2 API Manager's API Gateway remain unaffected.

CVE Details

CVSS v3.1 Score9.6
SeverityCRITICAL
CVSS VectorCVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H
Attack VectorADJACENT_NETWORK
ComplexityLOW
Privileges RequiredNONE
User InteractionNONE
Published10/16/2025
Last Modified11/21/2025
Sourcenvd
Honeypot Sightings0

Affected Products

wso2:api_control_planewso2:api_managerwso2:api_manager_analyticswso2:data_analytics_serverwso2:enterprise_integratorwso2:enterprise_mobility_managerwso2:enterprise_service_buswso2:identity_serverwso2:identity_server_analyticswso2:identity_server_as_key_managerwso2:open_banking_amwso2:open_banking_iamwso2:open_banking_kmwso2:traffic_managerwso2:universal_gateway

Weaknesses (CWE)

CWE-284

IOC Correlations

No correlations recorded

This product uses data from the NVD API but is not endorsed or certified by the NVD.