Account Enumeration Vulnerability in WSO2 Identity Server
CVE-2025-13736

3.7LOW

What is CVE-2025-13736?

The vulnerability in WSO2 Identity Server arises from the Multi-Attribute Login feature, which inadequately masks the existence of user accounts. When this feature is enabled, valid users' canonical usernames are displayed, while users that do not exist receive feedback echoing their input. This inconsistency can lead to unauthorized reveals of valid usernames, increasing susceptibility to brute force attacks and social engineering schemes. Attackers can exploit this knowledge to enhance the effectiveness of phishing campaigns or to launch targeted efforts aiming to access sensitive information and breach user accounts.

Affected Version(s)

WSO2 API Manager 3.1.0 < 3.1.0.351

WSO2 API Manager 3.2.0 < 3.2.0.455

WSO2 API Manager 4.0.0 < 4.0.0.375

References

CVSS V3.1

Score:
3.7
Severity:
LOW
Confidentiality:
Low
Integrity:
None
Availability:
Low
Attack Vector:
Network
Attack Complexity:
High
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.