← Back

CVE-2025-12737

nvd nist
Published: Sep 3, 2026Modified: Sep 9, 2026

JSON object

Loading...
8.4
Vector
CVSS:3.1/AV:A/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:H
Exploitability: 1.7 / Impact: 6.0
Source: ed10eef1-636d-4fbe-9993-6890dfa878f8 (Secondary)

Description

The administrative operations within the Carbon Console do not adequately validate specific user-supplied input. This oversight allows a malicious actor with administrative privileges to inject and execute arbitrary code remotely. Successful exploitation enables a threat actor with administrative privileges and Carbon Console access to execute remote arbitrary code through specific administrative operations, leading to a complete compromise of the affected system.

Affected (26)

8 products
Api Control Plane
Api Manager
Identity Server
Identity Server As Key Manager
Open Banking Am
Open Banking Iam
Traffic Manager
Universal Gateway
Configuration A
26 vulnerable
Vulnerable SoftwareAffected Versions
Wso2
From 4.5.0 to 4.5.0.36
Version 4.6.0
Wso2
From 3.1.0 to 3.1.0.349
From 3.2.0 to 3.2.0.453
From 3.2.1 to 3.2.1.73
From 4.0.0 to 4.0.0.373
From 4.1.0 to 4.1.0.236
From 4.2.0 to 4.2.0.176
From 4.3.0 to 4.3.0.88
From 4.4.0 to 4.4.0.52
From 4.5.0 to 4.5.0.35
Version 4.6.0
Wso2
From 5.10.0 to 5.10.0.378
From 5.11.0 to 5.11.0.425
From 6.0.0 to 6.0.0.252
From 6.1.0 to 6.1.0.253
From 7.0.0 to 7.0.0.130
From 7.1.0 to 7.1.0.38
Version 7.2.0
From 5.10.0 to 5.10.0.369
From 2.0.0 to 2.0.0.398
From 2.0.0 to 2.0.0.418
Wso2
From 4.5.0 to 4.5.0.34
Version 4.6.0
Wso2
From 4.5.0 to 4.5.0.34
Version 4.6.0

References (1)

Timeline

No history available yet.