← Back

CVE-2024-4598

nvd nist
Published: Sep 23, 2025Modified: Jun 17, 2026

JSON object

Loading...
6.5
Vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
Exploitability: 2.8 / Impact: 3.6
Source: ed10eef1-636d-4fbe-9993-6890dfa878f8 (Secondary)

Description

An information disclosure vulnerability exists in multiple WSO2 products due to improper implementation of the enrich mediator. Authenticated users may be able to view unintended business data from other mediation contexts because the internal state is not properly isolated or cleared between executions. This vulnerability does not impact user credentials or access tokens but may lead to leakage of sensitive business information handled during message flows.

Affected (6)

2 products
Api Manager
Micro Integrator
Configuration A
6 vulnerable
Vulnerable SoftwareAffected Versions
Wso2
From 3.2.0 to 3.2.0.422
From 3.2.1 to 3.2.1.42
From 4.1.0 to 4.1.0.152
From 4.3.0 to 4.3.0.55
Wso2
From 1.2.0 to 1.2.0.157
From 4.1.0 to 4.1.0.95

References (1)

Timeline

No history available yet.