Dismissed
(no matching packages found)
Permalink
CVE-2025-12737
8.4 HIGH
- CVSS version (CVSS): 3.1
- Attack Vector (AV): Adjacent (A)
- Attack Complexity (AC): Low (L)
- Privileges Required (PR): High (H)
- User Interaction (UI): None (N)
- Scope (S): Changed (C)
- Confidentiality (C): High (H)
- Integrity (I): High (H)
- Availability (A): High (H)
- Modified Attack Vector (MAV): Adjacent (A)
- Modified Attack Complexity (MAC): Low (L)
- Modified Privileges Required (MPR): High (H)
- Modified User Interaction (MUI): None (N)
- Modified Confidentiality (MC): High (H)
- Modified Scope (MS): Changed (C)
- Modified Integrity (MI): High (H)
- Modified Availability (MA): High (H)
Activity log
- Created & dismissed (no matching packages found) suggestion
Arbitrary Code Execution via Administrative Operations in Multiple WSO2 Products Allows Remote Code Execution
The administrative operations within the Carbon Console do not adequately validate specific user-supplied input. This oversight allows a malicious actor with administrative privileges to inject and execute arbitrary code remotely. Successful exploitation enables a threat actor with administrative privileges and Carbon Console access to execute remote arbitrary code through specific administrative operations, leading to a complete compromise of the affected system.
References
Affected products
WSO2 API Manager
- <4.6.0.1
- <4.4.0.52
- <3.2.1.73
- <4.1.0.236
- <4.0.0.373
- <3.2.0.453
- <3.1.0.349
- <4.5.0.35
- <4.2.0.176
- <4.3.0.88
- <3.1.0
WSO2 Identity Server
- <7.1.0.38
- <7.2.0.1
- <5.11.0.425
- <5.10.0.378
- <6.1.0.253
- <6.0.0.252
- <7.0.0.130
- <5.10.0
WSO2 Open Banking AM
- <2.0.0.398
- <2.0.0
WSO2 Traffic Manager
- <4.5.0.34
- <4.6.0.1
WSO2 Open Banking IAM
- <2.0.0.418
- <2.0.0
WSO2 API Control Plane
- <4.6.0.1
- <4.5.0.36
WSO2 Universal Gateway
- <4.5.0.34
- <4.6.0.1
WSO2 Identity Server as Key Manager
- <5.10.0
- <5.10.0.369