PT-2025-3690 · Wso2 · Wso2 Api Manager

Published

2025-01-14

·

Updated

2025-10-06

·

CVE-2024-7097

CVSS v3.1

4.3

Medium

VectorAV:A/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N
Name of the Vulnerable Software and Affected Versions WSO2 API Manager (affected versions not specified)
Description The issue allows for unauthenticated account creation, potentially leading to a fully compromised system. It requires the WSDLs of admin services to be enabled first.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Incorrect Authorization

Weakness Enumeration

Related Identifiers

CVE-2024-7097

Affected Products

Wso2 Api Manager