CVE-2025-5605mediumexplotación observadaCWE-290

CVE-2025-5605: fallo de gravedad media en WSO2 org.wso2.carbon:org.wso2.carbon.ui

Authentication Bypass via URI Manipulation in Multiple WSO2 Products' Management Console Leading to Partial Information Disclosure

Publicada el

50Vexday Risk Score

Corrige ahora. Ella explotación observada por VulnCheck y tiene exploit funcional público.

ssvc Actcvss 4.3epss 0.9%
de la publicación al arma
Publicada en NVD24 oct
VulnCheck+35d
probabilidad de explotación
0.9%top 43% de las CVE
explotación observada
síVulnCheck
An authentication bypass vulnerability exists in the Management Console of multiple WSO2 products. A malicious actor with access to the console can manipulate the request URI to bypass authentication and access certain restricted resources, resulting in partial information disclosure. The known exposure from this issue is limited to memory statistics. While the vulnerability does not allow full account compromise, it still enables unauthorized access to internal system details.
CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N