Dismissed
(no matching packages found)
Permalink
CVE-2025-14561
9.0 CRITICAL
- CVSS version (CVSS): 3.1
- Attack Vector (AV): Network (N)
- Attack Complexity (AC): Low (L)
- Privileges Required (PR): High (H)
- User Interaction (UI): None (N)
- Scope (S): Changed (C)
- Confidentiality (C): High (H)
- Integrity (I): High (H)
- Availability (A): Low (L)
- Modified Attack Vector (MAV): Network (N)
- Modified Attack Complexity (MAC): Low (L)
- Modified Privileges Required (MPR): High (H)
- Modified User Interaction (MUI): None (N)
- Modified Confidentiality (MC): High (H)
- Modified Scope (MS): Changed (C)
- Modified Integrity (MI): High (H)
- Modified Availability (MA): Low (L)
Activity log
- Created & dismissed (no matching packages found) suggestion
Access Control Bypass via Publisher REST APIs in Multiple WSO2 Products Allows Cross-Tenant Operations
In multi-tenant deployments, the Publisher REST APIs fail to enforce tenant isolation correctly. This allows a user in one tenant, possessing sufficient privileges to invoke these APIs, to perform operations that impact other tenants. The vulnerability allows a privileged user to perform publisher operations such as exposing or modifying API Metadata in another tenant environment. This impact is only realized in multi-tenant deployments.
References
Affected products
WSO2 API Manager
- <4.3.0.93
- <4.5.0.41
- <4.2.0.182
- <4.6.0.6
- <4.1.0.242
- <4.4.0.57
WSO2 Traffic Manager
- <4.5.0.40
- <4.6.0.6
WSO2 API Control Plane
- <4.5.0.42
- <4.6.0.7
WSO2 Universal Gateway
- <4.5.0.40
- <4.6.0.6
org.wso2.carbon.apimgt:org.wso2.carbon.apimgt.impl
- <9.20.74.388
- =<*
- <9.29.120.213
- <9.30.67.135
- <9.32.147.5
- <9.28.116.395
- <9.31.86.108
org.wso2.carbon.apimgt:org.wso2.carbon.apimgt.rest.api.util
- <9.20.74.388
- =<*
- <9.29.120.213
- <9.30.67.135
- <9.32.147.5
- <9.28.116.395
- <9.31.86.108