An information disclosure vulnerability exists in multiple WSO2 products due to improper implementation of the enrich mediator. Authenticated users may be able to view unintended business data from other mediation contexts because the internal state is not properly isolated or cleared between executions. This vulnerability does not impact user credentials or access tokens but may lead to leakage of sensitive business information handled during message flows.
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:NWso2 Api Manager
APPWso23.2.0 – 3.2.0.422 (excl.)3.2.1 – 3.2.1.42 (excl.)4.1.0 – 4.1.0.152 (excl.)4.3.0 – 4.3.0.55 (excl.)Wso2 Micro Integrator
APPWso21.2.0 – 1.2.0.157 (excl.)4.1.0 – 4.1.0.95 (excl.)
Related vulnerabilities
WSO2 — nieograniczony upload plików i RCE przez path traversal
WSO2: niedostateczne ograniczenia tokenów użytkowników — dostęp do Admin REST API
Błąd weryfikacji algorytmu JWT umożliwia nieautoryzowany dostęp (WSO2)
Pominięcie uwierzytelniania wieloetapowego w WSO2 Conditional Authentication
WSO2 API Manager – RCE przez upload pliku z uprawnieniami administratora