MEDIUM🇵🇱 Wersja polska

CVE-2024-4598

CVSS 6.5v3.1pub. 2025-09-23upd. 2026-01-09

An information disclosure vulnerability exists in multiple WSO2 products due to improper implementation of the enrich mediator. Authenticated users may be able to view unintended business data from other mediation contexts because the internal state is not properly isolated or cleared between executions. This vulnerability does not impact user credentials or access tokens but may lead to leakage of sensitive business information handled during message flows.

CVSS Vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
  • Wso2 Api Manager

    APP
    Wso2
    3.2.0 – 3.2.0.422 (excl.)3.2.1 – 3.2.1.42 (excl.)4.1.0 – 4.1.0.152 (excl.)4.3.0 – 4.3.0.55 (excl.)
  • Wso2 Micro Integrator

    APP
    Wso2
    1.2.0 – 1.2.0.157 (excl.)4.1.0 – 4.1.0.95 (excl.)
🔵
CHECK WITH VENDOR
No clear patch data available. Check vendor references.
CWE
References

Related vulnerabilities

CVE-2022-29464CRITICAL9.8⚠ KEVPL ✓same product

WSO2 — nieograniczony upload plików i RCE przez path traversal

CVE-2026-1728CRITICAL9.8PL ✓same product

WSO2: niedostateczne ograniczenia tokenów użytkowników — dostęp do Admin REST API

CVE-2026-5430CRITICAL10.0PL ✓same product

Błąd weryfikacji algorytmu JWT umożliwia nieautoryzowany dostęp (WSO2)

CVE-2025-15039CRITICAL9.4PL ✓same product

Pominięcie uwierzytelniania wieloetapowego w WSO2 Conditional Authentication

CVE-2025-13590CRITICAL9.1PL ✓same product

WSO2 API Manager – RCE przez upload pliku z uprawnieniami administratora