Information Disclosure Vulnerability in WSO2 Products
CVE-2024-4598

6.5MEDIUM

Key Information:

Vendor

Wso2

Vendor
CVE Published:
23 September 2025

What is CVE-2024-4598?

An information disclosure vulnerability exists across various WSO2 products due to the improper implementation of the enrich mediator. This flaw allows authenticated users to potentially view sensitive business data from other mediation contexts because the internal state is not adequately isolated or cleared during executions. While this vulnerability does not compromise user credentials or access tokens, it raises significant concerns about the inadvertent exposure of sensitive information handled in message flows.

Affected Version(s)

WSO2 API Manager 3.2.0 < 3.2.0.422

WSO2 API Manager 3.2.1 < 3.2.1.42

WSO2 API Manager 4.1.0 < 4.1.0.152

References

CVSS V3.1

Score:
6.5
Severity:
MEDIUM
Confidentiality:
High
Integrity:
None
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.
CVE-2024-4598 : Information Disclosure Vulnerability in WSO2 Products