← Retour aux CVEs
CVE-2025-9804
CRITICAL9.6
Description
An improper access control vulnerability exists in multiple WSO2 products due to insufficient permission enforcement in certain internal SOAP Admin Services and System REST APIs. A low-privileged user may exploit this flaw to perform unauthorized operations, including accessing server-level information. This vulnerability affects only internal administrative interfaces. APIs exposed through the WSO2 API Manager's API Gateway remain unaffected.
Details CVE
Score CVSS v3.19.6
SeveriteCRITICAL
Vecteur CVSSCVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H
Vecteur d'attaqueADJACENT_NETWORK
ComplexiteLOW
Privileges requisNONE
Interaction utilisateurNONE
Publie10/16/2025
Derniere modification11/21/2025
Sourcenvd
Observations honeypot0
Produits affectes
wso2:api_control_planewso2:api_managerwso2:api_manager_analyticswso2:data_analytics_serverwso2:enterprise_integratorwso2:enterprise_mobility_managerwso2:enterprise_service_buswso2:identity_serverwso2:identity_server_analyticswso2:identity_server_as_key_managerwso2:open_banking_amwso2:open_banking_iamwso2:open_banking_kmwso2:traffic_managerwso2:universal_gateway
Faiblesses (CWE)
CWE-284
References
https://security.docs.wso2.com/en/latest/security-announcements/security-advisories/2025/WSO2-2025-4503/(ed10eef1-636d-4fbe-9993-6890dfa878f8)
Correlations IOC
Aucune correlation enregistree
This product uses data from the NVD API but is not endorsed or certified by the NVD.