← All CVEs

CVE-2025-9804

critical · 9.6

An improper access control vulnerability exists in multiple WSO2 products due to insufficient permission enforcement in certain internal SOAP Admin Services and System REST APIs. A low-privileged user may exploit this flaw to perform unauthorized operations, including accessing server-level information. This vulnerability affects only internal administrative interfaces. APIs exposed through the WSO2 API Manager's API Gateway remain unaffected.

9.6
CVSS
0.6%
EPSS (exploit prob.)
45th
EPSS percentile
2025-10-16
Published

CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H

Weaknesses

CWE-284

Affected products

VendorProductAffected versions
wso2api_control_plane4.5.0
wso2api_manager2.0.0
wso2api_manager2.1.0
wso2api_manager2.2.0
wso2api_manager2.5.0
wso2api_manager2.6.0
wso2api_manager3.0.0
wso2api_manager3.1.0
wso2api_manager3.2.0
wso2api_manager3.2.1
wso2api_manager4.0.0
wso2api_manager4.1.0
wso2api_manager4.2.0
wso2api_manager4.3.0
wso2api_manager4.4.0
wso2api_manager4.5.0
wso2api_manager_analytics2.0.0
wso2api_manager_analytics2.1.0
wso2api_manager_analytics2.2.0
wso2api_manager_analytics2.5.0
wso2data_analytics_server3.1.0
wso2data_analytics_server3.2.0
wso2enterprise_integrator6.2.0
wso2enterprise_integrator6.3.0
wso2enterprise_mobility_manager2.2.0
wso2enterprise_service_bus5.0.0
wso2identity_server5.2.0
wso2identity_server5.3.0
wso2identity_server5.4.0
wso2identity_server5.4.1
wso2identity_server5.5.0
wso2identity_server5.6.0
wso2identity_server5.7.0
wso2identity_server5.8.0
wso2identity_server5.9.0
wso2identity_server5.10.0
wso2identity_server5.11.0
wso2identity_server6.0.0
wso2identity_server6.1.0
wso2identity_server7.0.0

Check a specific version with /api/v1/cve/match.

References

Query this programmatically:

curl https://evil-db.io/api/v1/cve/CVE-2025-9804