CVE-2025-5605: fallo de gravedad media en WSO2 org.wso2.carbon:org.wso2.carbon.ui
Authentication Bypass via URI Manipulation in Multiple WSO2 Products' Management Console Leading to Partial Information Disclosure
Publicada el
50Vexday Risk Score
Corrige ahora. Ella explotación observada por VulnCheck y tiene exploit funcional público.
ssvc Actcvss 4.3epss 0.9%
de la publicación al arma
Publicada en NVD24 oct
VulnCheck+35d
probabilidad de explotación
0.9%top 43% de las CVE
explotación observada
síVulnCheck
An authentication bypass vulnerability exists in the Management Console of multiple WSO2 products. A malicious actor with access to the console can manipulate the request URI to bypass authentication and access certain restricted resources, resulting in partial information disclosure.
The known exposure from this issue is limited to memory statistics. While the vulnerability does not allow full account compromise, it still enables unauthorized access to internal system details.
CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N
Productos afectados
WSO2 · org.wso2.carbon:org.wso2.carbon.uiWSO2 · WSO2 API Control PlaneWSO2 · WSO2 API ManagerWSO2 · WSO2 Enterprise IntegratorWSO2 · WSO2 Identity ServerWSO2 · WSO2 Identity Server as Key ManagerWSO2 · WSO2 Open Banking AMWSO2 · WSO2 Open Banking IAMWSO2 · WSO2 Traffic ManagerWSO2 · WSO2 Universal GatewayCVEs relacionadas — WSO2 org.wso2.carbon:org.wso2.carbon.ui
En el mismo producto, de las más peligrosas a las menos.
CVE-2026-5430CRITICALAuthentication Bypass via JWT Algorithm Mismatch in Multiple WSO2 Products Allows Account TakeoverEPSS 0.6%KEVCVE-2024-7074MEDIUMAuthenticated Arbitrary File Upload in Multiple WSO2 Products via SOAP Admin Service Leading to Remote Code ExecutionEPSS 17.2%CVE-2025-2905CRITICALAn XML External Entity (XXE) vulnerability in Multiple WSO2 ProductsEPSS 1.3%CVE-2025-3125MEDIUMAuthenticated Arbitrary File Upload in Multiple WSO2 Products via CarbonAppUploader Admin Service Leading to Remote Code ExecutionEPSS 0.9%CVE-2025-10611CRITICALPotential Broken Access Control in Multiple WSO2 Products via System REST APIsEPSS 0.8%CVE-2026-3418CRITICALArbitrary File Upload via System REST API in Multiple WSO2 Products Allows Remote Code ExecutionEPSS 0.8%