6.8
CVE-2024-6541
- EPSS 0.26%
- Veröffentlicht 06.08.2026 22:16:40
- Zuletzt bearbeitet 07.08.2026 18:17:05
- CVE-Watchlists
- Unerledigt
Information Disclosure and Integrity Violation via Improper Message Context Handling in Multiple WSO2 Products
The Class Mediator fails to correctly validate or sanitize `messageContext` properties when they are used to populate dynamic values. This allows authenticated users to potentially access or modify data across different system invocations that should be isolated. This weakness can lead to the disclosure of sensitive information belonging to other users or the unintended modification of system data by authenticated users. The exact impact depends on how `messageContext` properties are utilized within the affected WSO2 products.
Daten sind bereitgestellt durch das CVE Programm von einer CVE Numbering Authority (CNA) (Unstrukturiert).
HerstellerWSO2
≫
Produkt
WSO2 Micro Integrator
Default Statusunaffected
Version
0
Version <
1.2.0
Status
unknown
Version
1.2.0
Version <
1.2.0.163
Status
affected
Version
4.1.0
Version <
4.1.0.103
Status
affected
Version
4.3.0
Version <
4.3.0.7
Status
affected
HerstellerWSO2
≫
Produkt
WSO2 Enterprise Integrator
Default Statusunaffected
Version
0
Version <
6.6.0
Status
unknown
Version
6.6.0
Version <
6.6.0.205
Status
affected
HerstellerWSO2
≫
Produkt
WSO2 API Manager
Default Statusunaffected
Version
0
Version <
3.2.0
Status
unknown
Version
3.2.0
Version <
3.2.0.394
Status
affected
Version
3.2.1
Version <
3.2.1.21
Status
affected
Version
4.0.0
Version <
4.0.0.311
Status
affected
Version
4.1.0
Version <
4.1.0.167
Status
affected
Version
4.2.0
Version <
4.2.0.110
Status
affected
Version
4.3.0
Version <
4.3.0.24
Status
affected
HerstellerWSO2
≫
Produkt
WSO2-Synapse
Default Statusunknown
Version
2.1.7.wso2v182
Version <
2.1.7.wso2v182_93
Status
affected
Version
2.1.7.wso2v143
Version <
2.1.7.wso2v143_119
Status
affected
Version
2.1.7.wso2v183
Version <
2.1.7.wso2v183_62
Status
affected
Version
2.1.7.wso2v319
Version <
2.1.7.wso2v319_7
Status
affected
Version
2.1.7.wso2v227
Version <
2.1.7.wso2v227_88
Status
affected
Version
2.1.7.wso2v271
Version <
2.1.7.wso2v271_60
Status
affected
Version
4.0.0.wso2v119
Version <
4.0.0.wso2v119_3
Status
affected
Version
4.0.0.wso2v105
Version <
4.0.0.wso2v105_3
Status
affected
Version
4.0.0.wso2v20
Version <
4.0.0.wso2v20_63
Status
affected
Version <=
v4.0.0-wso2v*
Version
v4.0.0-wso2v121
Status
unaffected
VulnDex Vulnerability Enrichment
| Typ | Quelle | Score | Percentile |
|---|---|---|---|
| EPSS | FIRST.org | 0.26% | 0.171 |
| Quelle | Base Score | Exploit Score | Impact Score | Vector String |
|---|---|---|---|---|
| ed10eef1-636d-4fbe-9993-6890dfa878f8 | 6.8 | 1.6 | 5.2 |
CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:N
|
CWE-20 Improper Input Validation
The product receives input or data, but it does not validate or incorrectly validates that the input has the properties that are required to process the data safely and correctly.
https://security.docs.wso2.com/en/latest/security-announcements/security-advisories/2026/WSO2-2024-3520/