Vulnerabilidades em WSO2

95 resultados
Análise Vexday

Com 63 CVEs catalogadas e nenhuma atualmente listada no catálogo KEV da CISA, o WSO2 apresenta taxa de exploração ativa abaixo da média geral do catálogo, o que indica menor pressão imediata de ameaças confirmadas em campo. No entanto, 7 vulnerabilidades de severidade crítica e 13 surgidas nos últimos 90 dias sinalizam um ritmo de descoberta que exige monitoramento contínuo. A falha mais comum é CWE-79 (Cross-site Scripting), padrão que, embora frequentemente subestimado, pode viabilizar ataques de sequestro de sessão e roubo de credenciais em plataformas de integração como as oferecidas pelo vendor. A CVE mais perigosa ativa no momento, CVE-2024-7074, registra escore EPSS de 0,0976 — probabilidade ainda moderada de exploração iminente, mas suficiente para recomendar priorização no ciclo de patching das equipes responsáveis por ambientes WSO2.

CVE-2025-10908HIGHAccount Lock Bypass via Magic Link or Pass Key Authentication in WSO2 Identity Server Allows Unauthorized AccessEPSS 0.2%CVE-2025-6024MEDIUMCross-Site Scripting via Authentication Endpoint in Multiple WSO2 Products Allows Redirection to Malicious WebsitesEPSS 0.2%CVE-2024-1440MEDIUMOpen Redirection in Multiple WSO2 Products via Multi-Option Authentication EndpointEPSS 0.2%CVE-2024-7073MEDIUMUnauthenticated Server-Side Request Forgery (SSRF) in Multiple WSO2 Products via SOAP Admin ServicesEPSS 0.2%CVE-2025-12737HIGHArbitrary Code Execution via Administrative Operations in Multiple WSO2 Products Allows Remote Code ExecutionEPSS 0.2%CVE-2025-13166LOWUsername Enumeration via SMS OTP Flow in WSO2 Identity Server Allows User Account DiscoveryEPSS 0.2%CVE-2025-0672LOWAuthentication Bypass in Multiple WSO2 Products via Stale FIDO Credential AssociationEPSS 0.2%CVE-2024-6429MEDIUMContent Spoofing in Multiple WSO2 Products via Error Message InjectionEPSS 0.2%CVE-2024-7103MEDIUMReflected Cross-Site Scripting (XSS) in WSO2 Identity Server 7.0.0 Sub-Organization Login FlowEPSS 0.2%CVE-2026-3096MEDIUMReverse Tabnabbing via New Tab Navigation in Multiple WSO2 Products Allows Phishing and Credential TheftEPSS 0.2%CVE-2025-9955MEDIUMImproper Access Control in WSO2 Enterprise Integrator Product via SOAP Admin Services for Logs and User-Store ConfigurationEPSS 0.2%CVE-2025-13909MEDIUMInformation Disclosure via Multi-Tenant Authentication Flows in WSO2 Identity Server Allows Cross-Tenant PII ExposureEPSS 0.2%CVE-2025-5770MEDIUMReflected Cross-Site Scripting (XSS) in Authentication Endpoints of Multiple WSO2 ProductsEPSS 0.2%CVE-2024-3509MEDIUMStored Cross-Site Scripting (XSS) in Management Console of Multiple WSO2 Products via Rich Text EditorEPSS 0.2%CVE-2025-6508MEDIUMUser Interface Misrepresentation via Swagger UI Try-out Console in WSO2 API Manager Allows Sensitive Information Exposure or Unintended RequestsEPSS 0.2%CVE-2024-4867MEDIUMCross-Site Scripting via Developer Portal in WSO2 API Manager Enables UI Modification and Information RetrievalEPSS 0.2%CVE-2024-3511MEDIUMIncorrect Authorization in Multiple WSO2 Products Allows Unauthorized Access to Registry Versioned FilesEPSS 0.2%CVE-2025-4760MEDIUMAuthenticated Stored Cross-Site Scripting (XSS) in Multiple WSO2 Products via API Document Upload in PublisherEPSS 0.2%CVE-2025-14779LOWImproper Access Control via Secret Type Management API in WSO2 Identity ServerEPSS 0.2%CVE-2025-8154MEDIUMHTTP Header Injection via Webhook API in Multiple WSO2 Products Allows Response Header ManipulationEPSS 0.2%