Tokens issued to a low-privileged user are not sufficiently restricted, allowing them to be used to access product-level Admin REST APIs. Exploitation of this vulnerability allows a low-privileged user to invoke the Admin REST APIs of WSO2 products, potentially leading to full administrative account takeover. This requires the attacker to already possess a low-privileged user account and be able to obtain a valid token for it.
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:HWso2 Api Control Plane
APPWso24.5.0 – 4.5.0.49 (excl.)4.6.0 – 4.6.0.13 (excl.)Wso2 Api Manager
APPWso24.0.0 – 4.0.0.384 (excl.)4.1.0 – 4.1.0.248 (excl.)4.2.0 – 4.2.0.188 (excl.)4.3.0 – 4.3.0.99 (excl.)4.4.0 – 4.4.0.63 (excl.)4.5.0 – 4.5.0.48 (excl.)4.6.0 – 4.6.0.12 (excl.)Wso2 Traffic Manager
APPWso24.5.0 – 4.5.0.47 (excl.)4.6.0 – 4.6.0.12 (excl.)Wso2 Universal Gateway
APPWso24.5.0 – 4.5.0.48 (excl.)4.6.0 – 4.6.0.12 (excl.)
Related vulnerabilities
WSO2 — nieograniczony upload plików i RCE przez path traversal
Błąd weryfikacji algorytmu JWT umożliwia nieautoryzowany dostęp (WSO2)
Pominięcie uwierzytelniania wieloetapowego w WSO2 Conditional Authentication
WSO2 API Manager – RCE przez upload pliku z uprawnieniami administratora
Brak wymuszania uwierzytelniania mTLS w produktach WSO2 — nieautoryzowany dostęp administracyjny