An authentication bypass vulnerability exists in the Management Console of multiple WSO2 products. A malicious actor with access to the console can manipulate the request URI to bypass authentication and access certain restricted resources, resulting in partial information disclosure.
The known exposure from this issue is limited to memory statistics. While the vulnerability does not allow full account compromise, it still enables unauthorized access to internal system details.
References
| Link | Resource |
|---|---|
| https://security.docs.wso2.com/en/latest/security-announcements/security-advisories/2025/WSO2-2025-4115/ | Vendor Advisory |
Configurations
Configuration 1 (hide)
|
History
No history.
Information
Published : 2025-10-24 10:15
Updated : 2025-11-21 14:20
NVD link : CVE-2025-5605
Mitre link : CVE-2025-5605
CVE.ORG link : CVE-2025-5605
JSON object : View
Products Affected
wso2
- api_control_plane
- identity_server
- identity_server_as_key_manager
- traffic_manager
- open_banking_iam
- open_banking_am
- api_manager
- enterprise_integrator
- universal_gateway
CWE
CWE-290
Authentication Bypass by Spoofing
