Vulnerabilidades en WSO2

95 resultados
Análisis Vexday

Com 63 CVEs catalogadas e nenhuma atualmente listada no catálogo KEV da CISA, o WSO2 apresenta taxa de exploração ativa abaixo da média geral do catálogo, o que indica menor pressão imediata de ameaças confirmadas em campo. No entanto, 7 vulnerabilidades de severidade crítica e 13 surgidas nos últimos 90 dias sinalizam um ritmo de descoberta que exige monitoramento contínuo. A falha mais comum é CWE-79 (Cross-site Scripting), padrão que, embora frequentemente subestimado, pode viabilizar ataques de sequestro de sessão e roubo de credenciais em plataformas de integração como as oferecidas pelo vendor. A CVE mais perigosa ativa no momento, CVE-2024-7074, registra escore EPSS de 0,0976 — probabilidade ainda moderada de exploração iminente, mas suficiente para recomendar priorização no ciclo de patching das equipes responsáveis por ambientes WSO2.

CVE-2024-8008MEDIUMReflected Cross-Site Scripting (XSS) in Multiple WSO2 Products via JDBC User Store Connection ValidationEPSS 0.5%CVE-2023-6839MEDIUMDue to improper error handling, a REST API resource could expose a server side error containing an internal WSO2 specific package name in thEPSS 0.5%CVE-2023-6835MEDIUMMultiple WSO2 products have been identified as vulnerable due to lack of server-side input validation in the Forum feature, API rating couldEPSS 0.5%CVE-2023-6836MEDIUMMultiple WSO2 products have been identified as vulnerable due to an XML External Entity (XXE) attack abuses a widely available but rarely usEPSS 0.5%CVE-2023-6837HIGHIncorrect Authorization in Multiple WSO2 Products via Federated Authentication with JIT Provisioning Leading to User ImpersonationEPSS 0.5%CVE-2025-11093HIGHArbitrary Code Execution with higher privileged users in Multiple WSO2 Products via Script Mediator Engines (GraalJS and NashornJS)EPSS 0.4%CVE-2023-6838MEDIUMReflected XSS vulnerability can be exploited by tampering a request parameter in Authentication Endpoint. This can be performed in both authEPSS 0.4%CVE-2025-10713MEDIUMXML External Entity (XXE) Vulnerability in Multiple WSO2 Products Due to Improper XML Parser ConfigurationEPSS 0.4%CVE-2023-6911MEDIUMMultiple WSO2 products have been identified as vulnerable due to improper output encoding, a Stored Cross Site Scripting (XSS) attack can beEPSS 0.4%CVE-2025-15039CRITICALAccount Takeover via Conditional Authentication Script Logic in Multiple WSO2 ProductsEPSS 0.4%CVE-2026-2053HIGHUnauthenticated Server-Side Request Forgery via WS-Addressing in WSO2 API ManagerEPSS 0.4%CVE-2025-14561CRITICALAccess Control Bypass via Publisher REST APIs in Multiple WSO2 Products Allows Cross-Tenant OperationsEPSS 0.4%CVE-2024-2374HIGHXML External Entity Injection in Multiple WSO2 Products Allows Arbitrary file read and Denial of ServiceEPSS 0.4%CVE-2025-9973MEDIUMAuthorization Bypass via Adaptive Authentication in WSO2 Identity Server Allows Cross-Organization Account TakeoverEPSS 0.4%CVE-2026-3415HIGHXML External Entity (XXE) Injection via Schema Validation in Multiple WSO2 Products Allows File Reading and Denial of ServiceEPSS 0.3%CVE-2026-5430CRITICALAuthentication Bypass via JWT Algorithm Mismatch in Multiple WSO2 Products Allows Account TakeoverEPSS 0.3%CVE-2024-4598MEDIUMInformation Disclosure in Multiple WSO2 Products Due to Improper Handling in Enrich MediatorEPSS 0.3%CVE-2025-10470HIGHDenial-of-Service via Magic Link Authentication in WSO2 Identity Server Allows Service UnavailabilityEPSS 0.3%CVE-2024-7487MEDIUMImproper Authentication in WSO2 Identity Server 7.0.0 Allows Bypass of App-Native AuthenticationEPSS 0.3%CVE-2026-1728CRITICALPrivilege Escalation via System REST APIs in Multiple WSO2 Products Permits Admin Account TakeoverEPSS 0.3%