Vulnerability Monitor

The vendors, products, and vulnerabilities you care about

CVE-2025-9804


An improper access control vulnerability exists in multiple WSO2 products due to insufficient permission enforcement in certain internal SOAP Admin Services and System REST APIs. A low-privileged user may exploit this flaw to perform unauthorized operations, including accessing server-level information. This vulnerability affects only internal administrative interfaces. APIs exposed through the WSO2 API Manager's API Gateway remain unaffected.


Published

2025-10-16T13:15:42.130

Last Modified

2025-11-21T21:40:09.890

Status

Analyzed

Source

ed10eef1-636d-4fbe-9993-6890dfa878f8

Severity

CVSSv3.1: 9.6 (CRITICAL)

Weaknesses
  • Type: Secondary
    CWE-284

Affected Vendors & Products
Type Vendor Product Version/Range Vulnerable?
Application wso2 api_control_plane 4.5.0 Yes
Application wso2 api_manager 2.0.0 Yes
Application wso2 api_manager 2.1.0 Yes
Application wso2 api_manager 2.2.0 Yes
Application wso2 api_manager 2.5.0 Yes
Application wso2 api_manager 2.6.0 Yes
Application wso2 api_manager 3.0.0 Yes
Application wso2 api_manager 3.1.0 Yes
Application wso2 api_manager 3.2.0 Yes
Application wso2 api_manager 3.2.1 Yes
Application wso2 api_manager 4.0.0 Yes
Application wso2 api_manager 4.1.0 Yes
Application wso2 api_manager 4.2.0 Yes
Application wso2 api_manager 4.3.0 Yes
Application wso2 api_manager 4.4.0 Yes
Application wso2 api_manager 4.5.0 Yes
Application wso2 api_manager_analytics 2.0.0 Yes
Application wso2 api_manager_analytics 2.1.0 Yes
Application wso2 api_manager_analytics 2.2.0 Yes
Application wso2 api_manager_analytics 2.5.0 Yes
Application wso2 data_analytics_server 3.1.0 Yes
Application wso2 data_analytics_server 3.2.0 Yes
Application wso2 enterprise_integrator 6.2.0 Yes
Application wso2 enterprise_integrator 6.3.0 Yes
Application wso2 enterprise_mobility_manager 2.2.0 Yes
Application wso2 enterprise_service_bus 5.0.0 Yes
Application wso2 identity_server 5.2.0 Yes
Application wso2 identity_server 5.3.0 Yes
Application wso2 identity_server 5.4.0 Yes
Application wso2 identity_server 5.4.1 Yes
Application wso2 identity_server 5.5.0 Yes
Application wso2 identity_server 5.6.0 Yes
Application wso2 identity_server 5.7.0 Yes
Application wso2 identity_server 5.8.0 Yes
Application wso2 identity_server 5.9.0 Yes
Application wso2 identity_server 5.10.0 Yes
Application wso2 identity_server 5.11.0 Yes
Application wso2 identity_server 6.0.0 Yes
Application wso2 identity_server 6.1.0 Yes
Application wso2 identity_server 7.0.0 Yes
Application wso2 identity_server 7.1.0 Yes
Application wso2 identity_server_analytics 5.2.0 Yes
Application wso2 identity_server_analytics 5.3.0 Yes
Application wso2 identity_server_analytics 5.5.0 Yes
Application wso2 identity_server_analytics 5.6.0 Yes
Application wso2 identity_server_as_key_manager 5.3.0 Yes
Application wso2 identity_server_as_key_manager 5.5.0 Yes
Application wso2 identity_server_as_key_manager 5.6.0 Yes
Application wso2 identity_server_as_key_manager 5.7.0 Yes
Application wso2 identity_server_as_key_manager 5.9.0 Yes
Application wso2 identity_server_as_key_manager 5.10.0 Yes
Application wso2 open_banking_am 1.4.0 Yes
Application wso2 open_banking_am 1.5.0 Yes
Application wso2 open_banking_am 2.0.0 Yes
Application wso2 open_banking_iam 2.0.0 Yes
Application wso2 open_banking_km 1.4.0 Yes
Application wso2 open_banking_km 1.5.0 Yes
Application wso2 traffic_manager 4.5.0 Yes
Application wso2 universal_gateway 4.5.0 Yes

References