PT-2025-42461 · Wso2 · Wso2 Enterprise Integrator

Published

2025-10-16

·

Updated

2025-10-21

·

CVE-2025-9955

CVSS v3.1

5.7

Medium

VectorAV:A/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
Name of the Vulnerable Software and Affected Versions WSO2 Enterprise Integrator (affected versions not specified)
Description An access control issue exists in WSO2 Enterprise Integrator due to inadequate permission restrictions on internal SOAP admin services concerning system logs and user-store configuration. A user with limited privileges can access log data and user-store configuration details that should not be accessible at their privilege level. This may allow unauthorized visibility into internal operational details, potentially aiding in further exploitation or reconnaissance.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Incorrect Authorization

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2025-9955

Affected Products

Wso2 Enterprise Integrator