Improper Access Control in WSO2 Products
CVE-2025-9804

8.9HIGH

What is CVE-2025-9804?

An improper access control vulnerability exists in multiple WSO2 products due to inadequate permission enforcement in specific internal SOAP Admin Services and System REST APIs. This vulnerability allows a low-privileged user to potentially perform unauthorized operations, including the retrieval of sensitive server-level information. Note that the APIs exposed through the WSO2 API Manager's API Gateway are not impacted by this flaw, emphasizing the need for vigilant management of internal administrative interfaces.

Affected Version(s)

API Manager Analytics 2.0.0 < 2.0.0.14

API Manager Analytics 2.1.0 < 2.1.0.19

API Manager Analytics 2.2.0 < 2.2.0.30

References

CVSS V3.1

Score:
8.9
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Adjacent Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

crnković
.
CVE-2025-9804 : Improper Access Control in WSO2 Products