← Back

CVE-2025-5605

Published: Oct 24, 2025Modified: Jun 17, 2026

JSON object

Loading...
5.3
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N
Exploitability: 3.9 / Impact: 1.4
Source: NVD

Description

An authentication bypass vulnerability exists in the Management Console of multiple WSO2 products. A malicious actor with access to the console can manipulate the request URI to bypass authentication and access certain restricted resources, resulting in partial information disclosure. The known exposure from this issue is limited to memory statistics. While the vulnerability does not allow full account compromise, it still enables unauthorized access to internal system details.

Affected (22)

9 products
Api Control Plane
Api Manager
Enterprise Integrator
Identity Server
Identity Server As Key Manager
Open Banking Am
Open Banking Iam
Traffic Manager
Universal Gateway
Configuration A
22 vulnerable
Vulnerable SoftwareAffected Versions
Version 4.5.0
Wso2
Version 3.1.0
Version 3.2.0
Version 3.2.1
Version 4.0.0
Version 4.1.0
Version 4.2.0
Version 4.3.0
Version 4.4.0
Version 4.5.0
Version 6.6.0
Wso2
Version 5.10.0
Version 5.11.0
Version 6.0.0
Version 6.1.0
Version 7.0.0
Version 7.1.0
Version 5.10.0
Version 2.0.0
Version 2.0.0
Version 4.5.0
Version 4.5.0

References (1)

Timeline

No history available yet.