Beveiligingsadvies

CVE-2025-9804

CVE-kwetsbaarheidsdetails - eXtreme Datacenter Security Operations

Gepubliceerd 2025-10-16 12:33:45
Laatst bijgewerkt 2025-10-17 16:01:25
Toegewezen door WSO2
CVSS-score 9.6
Status PUBLISHED

Beschrijving

An improper access control vulnerability exists in multiple WSO2 products due to insufficient permission enforcement in certain internal SOAP Admin Services and System REST APIs. A low-privileged user may exploit this flaw to perform unauthorized operations, including accessing server-level information. This vulnerability affects only internal administrative interfaces. APIs exposed through the WSO2 API Manager's API Gateway remain unaffected.