An improper access control vulnerability exists in multiple WSO2 products due to insufficient permission enforcement in certain internal SOAP Admin Services and System REST APIs. A low-privileged user may exploit this flaw to perform unauthorized operations, including accessing server-level information.
This vulnerability affects only internal administrative interfaces. APIs exposed through the WSO2 API Manager's API Gateway remain unaffected.
References
| Link | Resource |
|---|---|
| https://security.docs.wso2.com/en/latest/security-announcements/security-advisories/2025/WSO2-2025-4503/ | Vendor Advisory |
Configurations
Configuration 1 (hide)
|
History
No history.
Information
Published : 2025-10-16 13:15
Updated : 2025-11-21 21:40
NVD link : CVE-2025-9804
Mitre link : CVE-2025-9804
CVE.ORG link : CVE-2025-9804
JSON object : View
Products Affected
wso2
- api_control_plane
- identity_server
- open_banking_km
- universal_gateway
- enterprise_mobility_manager
- identity_server_as_key_manager
- open_banking_iam
- traffic_manager
- open_banking_am
- data_analytics_server
- api_manager
- enterprise_integrator
- identity_server_analytics
- api_manager_analytics
- enterprise_service_bus
CWE
CWE-284
Improper Access Control
