PT-2025-42463 · Wso2 · Wso2 Products
Crnković
·
Published
2025-10-16
·
Updated
2025-11-21
·
CVE-2025-9804
CVSS v3.1
8.9
High
| Vector | AV:A/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:L |
Name of the Vulnerable Software and Affected Versions
WSO2 products (affected versions not specified)
Description
An improper access control issue exists in multiple WSO2 products due to insufficient permission enforcement in certain internal SOAP Admin Services and System REST APIs. This allows a low-privileged user to perform unauthorized operations, including accessing server-level information. The vulnerability affects only internal administrative interfaces and does not impact APIs exposed through the WSO2 API Manager's API Gateway. The vulnerability allows unauthorized access to server information through internal SOAP Admin Services. The issue stems from insufficient permission enforcement within internal SOAP Admin Services and System REST APIs.
Recommendations
At the moment, there is no information about a newer version that contains a fix for this vulnerability.
Improper Access Control
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Wso2 Products