PT-2025-42463 · Wso2 · Wso2 Products

Crnković

·

Published

2025-10-16

·

Updated

2025-11-21

·

CVE-2025-9804

CVSS v3.1

8.9

High

VectorAV:A/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:L
Name of the Vulnerable Software and Affected Versions WSO2 products (affected versions not specified)
Description An improper access control issue exists in multiple WSO2 products due to insufficient permission enforcement in certain internal SOAP Admin Services and System REST APIs. This allows a low-privileged user to perform unauthorized operations, including accessing server-level information. The vulnerability affects only internal administrative interfaces and does not impact APIs exposed through the WSO2 API Manager's API Gateway. The vulnerability allows unauthorized access to server information through internal SOAP Admin Services. The issue stems from insufficient permission enforcement within internal SOAP Admin Services and System REST APIs.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Improper Access Control

Weakness Enumeration

Related Identifiers

CVE-2025-9804

Affected Products

Wso2 Products