MEDIUM🇬🇧 English

CVE-2024-4598

CVSS 6.5v3.1pub. 2025-09-23upd. 2026-01-09

An information disclosure vulnerability exists in multiple WSO2 products due to improper implementation of the enrich mediator. Authenticated users may be able to view unintended business data from other mediation contexts because the internal state is not properly isolated or cleared between executions. This vulnerability does not impact user credentials or access tokens but may lead to leakage of sensitive business information handled during message flows.

oryginał EN
CVSS Vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
  • Wso2 Api Manager

    APP
    Wso2
    3.2.0 – 3.2.0.422 (bez)3.2.1 – 3.2.1.42 (bez)4.1.0 – 4.1.0.152 (bez)4.3.0 – 4.3.0.55 (bez)
  • Wso2 Micro Integrator

    APP
    Wso2
    1.2.0 – 1.2.0.157 (bez)4.1.0 – 4.1.0.95 (bez)
🔵
ZWERYFIKUJ U PRODUCENTA
Brak jednoznacznych danych o patchu. Sprawdź referencje od producenta.
CWE
Referencje

Powiązane podatności

CVE-2022-29464CRITICAL9.8⚠ KEVPL ✓ten sam produkt

WSO2 — nieograniczony upload plików i RCE przez path traversal

CVE-2026-1728CRITICAL9.8PL ✓ten sam produkt

WSO2: niedostateczne ograniczenia tokenów użytkowników — dostęp do Admin REST API

CVE-2026-5430CRITICAL10.0PL ✓ten sam produkt

Błąd weryfikacji algorytmu JWT umożliwia nieautoryzowany dostęp (WSO2)

CVE-2025-15039CRITICAL9.4PL ✓ten sam produkt

Pominięcie uwierzytelniania wieloetapowego w WSO2 Conditional Authentication

CVE-2025-13590CRITICAL9.1PL ✓ten sam produkt

WSO2 API Manager – RCE przez upload pliku z uprawnieniami administratora